CVE-2009-0265: High severity ISC BIND vulnerability
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVPVerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0265?
CVE-2009-0265 is classified as a high severity vulnerability due to its potential to allow remote attackers to bypass certificate chain validation.
How do I fix CVE-2009-0265?
To fix CVE-2009-0265, you should upgrade to BIND 9.6.1 or later, where the vulnerability has been addressed.
What versions of BIND are affected by CVE-2009-0265?
CVE-2009-0265 affects BIND versions 9.6.0 and earlier, as well as several specified older versions of BIND 8.
What types of attacks can exploit CVE-2009-0265?
CVE-2009-0265 can be exploited by attackers who craft malformed SSL/TLS signatures to bypass authentication.
Is CVE-2009-0265 a remote exploit?
Yes, CVE-2009-0265 is a remote exploit that allows attackers to target vulnerable BIND servers over the network.