First published: Wed Sep 06 2006(Updated: )
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BIND 9 | =9.3 | |
BIND 9 | =9.2.5 | |
BIND 9 | =9.3.2 | |
BIND 9 | =9.2.2 | |
BIND 9 | =9.3.0 | |
BIND 9 | =9.2.4 | |
BIND 9 | =9.2.1 | |
BIND 9 | =9.3.1 | |
BIND 9 | =9.2.3 | |
BIND 9 | =9.2.0 | |
BIND 9 | =9.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4096 is considered a critical vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2006-4096, upgrade BIND to version 9.2.6-P1 or 9.3.2-P1 or later.
CVE-2006-4096 affects BIND versions prior to 9.2.6-P1 and those in the 9.3.x series before 9.3.2-P1.
Yes, CVE-2006-4096 can be exploited remotely by sending a flood of recursive queries.
CVE-2006-4096 facilitates denial of service attacks through crashes caused by excessive queries.