First published: Tue Oct 05 2010(Updated: )
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BIND 9 | =9.7.2 | |
BIND 9 | =9.7.2-p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0218 has a medium severity rating due to its potential to expose sensitive information through unauthorized access to the DNS cache.
To fix CVE-2010-0218, upgrade to BIND version 9.7.2-P2 or later, which resolves the ACL issue.
CVE-2010-0218 affects ISC BIND versions 9.7.2 and 9.7.2-P1.
CVE-2010-0218 is a vulnerability that involves improper access control in DNS queries.
Not patching CVE-2010-0218 may expose sensitive information to remote attackers, compromising the security of your DNS system.