CVE-2006-4095: High severity ISC BIND vulnerability
Published Sep 6, 2006
·Updated
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Affected Software
17 affected components
ISC BIND=9.3
ISC BIND=9.2.5
ISC BIND=9.3.2
ISC BIND=9.3.0
ISC BIND=9.2.4
ISC BIND=9.3.1
ISC BIND=9.2.3
ISC BIND=9.2.6
ISC BIND<=9.2.6
ISC BIND>=9.3.0<=9.3.2
Canonical Ubuntu Linux=5.04
Canonical Ubuntu Linux=5.10
Canonical Ubuntu Linux=6.06
Apple iOS and macOS<10.3.9
Apple iOS and macOS>=10.4.0<10.4.9
Apple Mac OS X Server<10.3.9
Apple Mac OS X Server>=10.4.0<10.4.9
Remediation
Patch Available
Event History
Sep 6, 2006
CVE Published
12:04 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4095?
The severity of CVE-2006-4095 is considered high as it allows remote attackers to cause denial of service by crashing the BIND service.
2
How do I fix CVE-2006-4095?
To fix CVE-2006-4095, upgrade to BIND version 9.3.2-P1 or later, or 9.2.6-P1 or later.
3
What systems are affected by CVE-2006-4095?
CVE-2006-4095 affects various versions of ISC BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1.
4
What type of vulnerability is CVE-2006-4095?
CVE-2006-4095 is a denial of service vulnerability caused by an assertion failure when handling specific SIG queries.
5
Can CVE-2006-4095 be exploited remotely?
Yes, CVE-2006-4095 can be exploited remotely by sending crafted SIG queries to the vulnerable BIND server.