MEDIUM
bind: DDoS (traffic amplification) via DNS queries with spoofed IP addresses due to additional information delegation to arbitrary IP addresses
Published Mar 3, 2006
5.0
MEDIUMCVSS 2.0
EPSS 58.03%
Description
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 5 and 6 and version of bind97 as shipped with Red Hat Enterprise Linux 5 as in the default configuration the named service accept DNS queries only from localhost.
Weaknesses (0)
No CWE recorded.
References (8)
- http://dns.measurement-factory.com/surveys/sum1.html x_refsource_MISC
- http://kb.isc.org/article/AA-00269 x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/426368/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf x_refsource_MISCPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-0987 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=873618 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2006-0987
- https://www.cve.org/CVERecord?id=CVE-2006-0987
| Link | Providers | Tags |
|---|---|---|
| http://dns.measurement-factory.com/surveys/sum1.html | x_refsource_MISC | |
| http://kb.isc.org/article/AA-00269 | x_refsource_CONFIRM | |
| http://www.securityfocus.com/archive/1/426368/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf | x_refsource_MISCPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2006-0987 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=873618 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2006-0987 | ||
| https://www.cve.org/CVERecord?id=CVE-2006-0987 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 3, 2006
Updated Aug 7, 2024
Reserved Mar 3, 2006
Link CVE-2006-0987
CISA Vulnrichment
Updated n/a