MEDIUM · 4.3

CVE-2003-0914

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

Vulnerability Description

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
IscBind8.2.3
NixuNamesurferstandard_3.0.1
CompaqTru644.0f
FreebsdFreebsd4.4
HpHp-Ux11.00
IbmAix5.1l
NetbsdNetbsd1.6
ScoUnixware7.1.1
SunSolaris7.0
SunSunos5.7

References

FAQ

What is CVE-2003-0914?

CVE-2003-0914 is a vulnerability with a CVSS score of 4.3 (MEDIUM). ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

How severe is CVE-2003-0914?

CVE-2003-0914 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0914?

Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind, Nixu Namesurfer, Compaq Tru64, Freebsd Freebsd, Hp Hp-Ux.