First published: Wed Sep 06 2006(Updated: )
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND 9 | <=9.2.6 | |
ISC BIND 9 | >=9.3.0<=9.3.2 | |
Ubuntu | =5.04 | |
Ubuntu | =5.10 | |
Ubuntu | =6.06 | |
Apple iOS and macOS | <10.3.9 | |
Apple iOS and macOS | >=10.4.0<10.4.9 | |
Apple macOS Server | <10.3.9 | |
Apple macOS Server | >=10.4.0<10.4.9 | |
ISC BIND 9 | =9.3 | |
ISC BIND 9 | =9.2.5 | |
ISC BIND 9 | =9.3.2 | |
ISC BIND 9 | =9.3.0 | |
ISC BIND 9 | =9.2.4 | |
ISC BIND 9 | =9.3.1 | |
ISC BIND 9 | =9.2.3 | |
ISC BIND 9 | =9.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-4095 is considered high as it allows remote attackers to cause denial of service by crashing the BIND service.
To fix CVE-2006-4095, upgrade to BIND version 9.3.2-P1 or later, or 9.2.6-P1 or later.
CVE-2006-4095 affects various versions of ISC BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1.
CVE-2006-4095 is a denial of service vulnerability caused by an assertion failure when handling specific SIG queries.
Yes, CVE-2006-4095 can be exploited remotely by sending crafted SIG queries to the vulnerable BIND server.