BIND upstream fix for CVE-2009-4022 is incomplete
Published Jan 22, 2010
4.0
MEDIUMCVSS 2.0
EPSS 6.78%
Description
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.
Affected products
No data.
- 9.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.1
- 9.0.1
- 9.0.1
- 9.1
- 9.1.0
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.1
- 9.1.2
- 9.1.2
- 9.1.3
- 9.1.3
- 9.1.3
- 9.1.3
- 9.2
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.0
- 9.2.1
- 9.2.1
- 9.2.1
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.2
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.3
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.4
- 9.2.5
- 9.2.5
- 9.2.5
- 9.2.6
- 9.2.6
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.7
- 9.2.8
- 9.2.9
- 9.2.9
- 9.3
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.0
- 9.3.1
- 9.3.1
- 9.3.1
- 9.3.2
- 9.3.2
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.3
- 9.3.4
- 9.3.5
- 9.3.5
- 9.3.5
- 9.3.6
- 9.3.6
- 9.4
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.0
- 9.4.1
- 9.4.2
- 9.4.2
- 9.4.2
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.4.3
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.0
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.6.1
- 9.7.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.0
- 9.10.1
- 9.10.1
- 9.10.1
- 9.10.1
- 9.10.1
- 9.10.1
- 9.10.1
- 9.10.2
- 9.10.2
- 9.10.2
- 9.10.2
- 9.10.2
- 9.10.2
- 9.10.2
- 9.10.3
- 9.10.3
- 9.10.3
- 9.10.3
- 9.10.3
- 9.10.3
No data.
Red Hat Enterprise Linux 5
bind-30:9.3.6-4.P1.el5_4.2
Fixed · RHSA-2010:0062
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind-30:9.3.6-4.P1.el5_4.2 | Fixed | RHSA-2010:0062 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.78% (0.06775) | 93.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.78% (0.06775) | 93.13th | v5 (v2026.06.15) |
| May 17, 2025 | 4.88% (0.04877) | 88.99th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.83% (0.03834) | 87.07th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.50% (0.09495) | 87.94th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.83% (0.03834) | 87.38th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.56% (0.02562) | 89.91th | v3 (v2023.03.01) |
| Mar 5, 2024 | 0.91% (0.00907) | 82.32th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.91% (0.00907) | 80.31th | v3 (v2023.03.01) |
| Mar 6, 2023 | 14.53% (0.14528) | 95.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 14.53% (0.14528) | 95.48th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.53% (0.14528) | 91.13th | v2 (v2022.01.01) |
No CWE recorded.
References (23)
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=oss-security&m=126393609503704&w=2 mailing-listx_refsource_MLIST
- http://marc.info/?l=oss-security&m=126399602810086&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/38219 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38240 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40086 third-party-advisoryx_refsource_SECUNIA
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018 x_refsource_CONFIRM
- http://www.debian.org/security/2010/dsa-2054 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:021 vendor-advisoryx_refsource_MANDRIVA
- http://www.ubuntu.com/usn/USN-888-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/0176 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/0622 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1352 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0290 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=554851 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=557121 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-0290
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6815 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7512 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8884 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2010-0062.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2010-0290
- https://www.isc.org/advisories/CVE-2009-4022v6 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.