CVE-2010-0382: High severity ISC BIND vulnerability
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0382?
CVE-2010-0382 has been classified as a high severity vulnerability due to the potential impact it could have on system security.
How do I fix CVE-2010-0382?
To resolve CVE-2010-0382, it is recommended to upgrade to BIND version 9.4.3-P5 or later, or to an appropriate secure version of BIND.
What are the affected versions of BIND for CVE-2010-0382?
CVE-2010-0382 affects ISC BIND versions 9.0.x through 9.3.x, as well as several specified versions up to 9.7.0 beta.
What type of attack does CVE-2010-0382 involve?
CVE-2010-0382 could allow remote attackers to exploit the handling of out-of-bailiwick data in DNS responses to impact system security.
Is CVE-2010-0382 a remote code execution vulnerability?
CVE-2010-0382 does not explicitly state that it allows remote code execution, but it enables potential exploits via crafted DNS responses.