CVE-2010-3614: Input Validation
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3614?
CVE-2010-3614 has been classified as a high severity vulnerability due to its potential to cause denial of service during DNSSEC validation.
How do I fix CVE-2010-3614?
To fix CVE-2010-3614, upgrade to BIND versions 9.6.2-P3, 9.7.2-P3, 9.4-ESV-R4, or 9.6-ESV-R3 or later.
What are the affected software versions for CVE-2010-3614?
CVE-2010-3614 affects BIND versions prior to 9.6.2-P3, 9.7.2-P3, 9.4-ESV-R4, and 9.6-ESV-R3.
Who is impacted by CVE-2010-3614?
Any users or organizations running vulnerable versions of BIND that perform DNSSEC validations are at risk from CVE-2010-3614.
What kind of attacks can CVE-2010-3614 allow?
CVE-2010-3614 can allow remote attackers to trigger a denial of service condition in the affected instances of BIND.