bind: cache poisoning using not validated DNSSEC responses
Published Nov 25, 2009
2.6
LOWCVSS 2.0
EPSS 7.95%
Description
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
Affected products
No data.
- 9.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.1
- 9.0.1
- 9.0.1
- 9.1
- 9.1.0
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.2
- 9.1.2
- 9.1.3
- 9.1.3
- 9.1.3
- 9.1.3
- 9.2
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.1
- 9.2.1
- 9.2.1
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.5
- 9.2.5
- 9.2.5
- 9.2.6
- 9.2.6
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.8
- 9.2.9
- 9.2.9
- 9.3
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.1
- 9.3.1
- 9.3.1
- 9.3.2
- 9.3.2
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.4
- 9.3.5
- 9.3.5
- 9.3.5
- 9.3.6
- 9.3.6
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.1
- 9.4.2
- 9.4.2
- 9.4.2
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.2
- 9.5.2
- 9.5.2
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
No data.
Red Hat Enterprise Linux 5
bind-30:9.3.6-4.P1.el5_4.1
Fixed · RHSA-2009:1620
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind-30:9.3.6-4.P1.el5_4.1 | Fixed | RHSA-2009:1620 |
No package ranges for this CVE.
Remediation
Red Hat statement
While this flaw exists in all 9.x versions, we do not plan to release bind updates for Red Hat Enterprise Linux 3 and 4 including this fix. The version of bind shipped in those products is 9.2.4, which has an older DNSSEC implementation, which is incompatible with currently used DNSSEC version and can not be used to secure communication with current public internet DNS servers. This flaw does not introduce additional risks to bind installations that are not using DNSSEC, as a successful attack requires bypass of other cache poisoning protections (such as random query source ports and transaction ids). This flaw only allows for the bypass of protection provided by DNSSEC.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 7.95% (0.07952) | 94.57th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.95% (0.07952) | 93.98th | v5 (v2026.06.15) |
| Jun 13, 2026 | 21.60% (0.21596) | 95.86th | v4 (v2025.03.14) |
| Mar 30, 2025 | 20.04% (0.20044) | 95.01th | v4 (v2025.03.14) |
| Mar 29, 2025 | 33.12% (0.33122) | 95.16th | v4 (v2025.03.14) |
| Mar 17, 2025 | 20.04% (0.20044) | 95.01th | v4 (v2025.03.14) |
| Dec 17, 2024 | 25.45% (0.25447) | 96.69th | v3 (v2023.03.01) |
| May 3, 2024 | 1.29% (0.01286) | 85.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.29% (0.01286) | 83.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 13.24% (0.13244) | 95.70th | v2 (v2022.01.01) |
| Jul 18, 2022 | 13.24% (0.13244) | 95.46th | v2 (v2022.01.01) |
| Jul 17, 2022 | 3.93% (0.03932) | 85.06th | v2 (v2022.01.01) |
| Apr 1, 2022 | 13.24% (0.13244) | 95.32th | v2 (v2022.01.01) |
| Feb 4, 2022 | 13.24% (0.13244) | 90.53th | v2 (v2022.01.01) |
No CWE recorded.
References (47)
- ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt x_refsource_CONFIRM
- http://aix.software.ibm.com/aix/efixes/security/bind9_advisory.asc x_refsource_CONFIRM
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLIST
- http://osvdb.org/60493 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/37426 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37491 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38219 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38240 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38834 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39334 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40730 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021660.1-1 vendor-advisoryx_refsource_SUNALERT
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT5002 x_refsource_CONFIRM
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018 x_refsource_CONFIRM
- http://www.ibm.com/support/docview.wss?uid=isg1IZ68597 vendor-advisoryx_refsource_AIXAPAR
- http://www.ibm.com/support/docview.wss?uid=isg1IZ71667 vendor-advisoryx_refsource_AIXAPAR
- http://www.ibm.com/support/docview.wss?uid=isg1IZ71774 vendor-advisoryx_refsource_AIXAPAR
- http://www.kb.cert.org/vuls/id/418861 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:304 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2009/11/24/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/11/24/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/11/24/8 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2009-1620.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/bid/37118 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-888-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/3335 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/0176 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/0622 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-4022 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=538744 x_refsource_CONFIRMPatchIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54416 vdb-entryx_refsource_XF
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488 x_refsource_CONFIRM
- https://issues.rpath.com/browse/RPL-3152 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2009-4022
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10821 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11745 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7261 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7459 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-4022
- https://www.isc.org/advisories/CVE-2009-4022v6 x_refsource_CONFIRMVendor Advisory
- https://www.isc.org/advisories/CVE2009-4022 x_refsource_CONFIRMVendor Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01172.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01188.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.