BIND DNSSEC NSEC/NSEC3 validation code could cause bogus NXDOMAIN responses
Published Jan 22, 2010
4.3
MEDIUMCVSS 2.0
EPSS 9.36%
Description
ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Affected products
No data.
- 9.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.1
- 9.0.1
- 9.0.1
- 9.1
- 9.1.0
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.2
- 9.1.2
- 9.1.3
- 9.1.3
- 9.1.3
- 9.1.3
- 9.2
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.1
- 9.2.1
- 9.2.1
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.5
- 9.2.5
- 9.2.5
- 9.2.6
- 9.2.6
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.8
- 9.2.9
- 9.2.9
- 9.3
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.1
- 9.3.1
- 9.3.1
- 9.3.2
- 9.3.2
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.4
- 9.3.5
- 9.3.5
- 9.3.5
- 9.3.6
- 9.3.6
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.1
- 9.4.2
- 9.4.2
- 9.4.2
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.5
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.0
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.1
- 9.5.2
- 9.5.2
- 9.5.2
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.7.0
No data.
Red Hat Enterprise Linux 5
bind-30:9.3.6-4.P1.el5_4.2
Fixed · RHSA-2010:0062
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind-30:9.3.6-4.P1.el5_4.2 | Fixed | RHSA-2010:0062 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.36% (0.09363) | 95.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.36% (0.09363) | 94.74th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.84% (0.01836) | 81.33th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.98% (0.03975) | 80.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.84% (0.01836) | 81.75th | v4 (v2025.03.14) |
| Dec 17, 2024 | 12.89% (0.12891) | 95.48th | v3 (v2023.03.01) |
| May 3, 2024 | 1.26% (0.01262) | 85.51th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.26% (0.01262) | 83.46th | v3 (v2023.03.01) |
| Mar 6, 2023 | 14.53% (0.14528) | 95.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 14.53% (0.14528) | 95.48th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.53% (0.14528) | 91.13th | v2 (v2022.01.01) |
References (39)
- ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt x_refsource_CONFIRM
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034196.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034202.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=127195582210247&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/38169 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38219 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38240 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39334 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/39582 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/40086 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1023474 vdb-entryx_refsource_SECTRACK
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT5002 x_refsource_CONFIRM
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018 x_refsource_CONFIRM
- http://www.debian.org/security/2010/dsa-2054 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/360341 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:021 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/61853 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/37865 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-888-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/0176 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/0622 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/0981 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1352 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0097 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=554851 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55753 vdb-entryx_refsource_XF
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2010-0097
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12205 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7212 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7430 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9357 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2010-0062.html vendor-advisoryx_refsource_REDHAT
- https://rhn.redhat.com/errata/RHSA-2010-0095.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2010-0097
- https://www.isc.org/advisories/CVE-2010-0097 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.