CVE-2006-4096: Medium severity ISC BIND vulnerability
Published Sep 6, 2006
·Updated
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty.
Affected Software
11 affected components
ISC BIND=9.2.0
ISC BIND=9.2.1
ISC BIND=9.2.2
ISC BIND=9.2.3
ISC BIND=9.2.4
ISC BIND=9.2.5
ISC BIND=9.2.6
ISC BIND=9.3
ISC BIND=9.3.0
ISC BIND=9.3.1
ISC BIND=9.3.2
Remediation
Patch Available
Event History
Sep 6, 2006
CVE Published
12:04 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4096?
CVE-2006-4096 is considered a critical vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2006-4096?
To mitigate CVE-2006-4096, upgrade BIND to version 9.2.6-P1 or 9.3.2-P1 or later.
3
Which versions of BIND are affected by CVE-2006-4096?
CVE-2006-4096 affects BIND versions prior to 9.2.6-P1 and those in the 9.3.x series before 9.3.2-P1.
4
Can CVE-2006-4096 be exploited remotely?
Yes, CVE-2006-4096 can be exploited remotely by sending a flood of recursive queries.
5
What type of attack does CVE-2006-4096 facilitate?
CVE-2006-4096 facilitates denial of service attacks through crashes caused by excessive queries.