Vulnerability Description
ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Isc | Bind | 9.7.2 |
Related Weaknesses (CWE)
References
- http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.htmlPatch
- http://www.kb.cert.org/vuls/id/784855US Government Resource
- https://lists.isc.org/pipermail/bind-announce/2010-September/000655.htmlVendor Advisory
- http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.htmlPatch
- http://www.kb.cert.org/vuls/id/784855US Government Resource
- https://lists.isc.org/pipermail/bind-announce/2010-September/000655.htmlVendor Advisory
FAQ
What is CVE-2010-0218?
CVE-2010-0218 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive infor...
How severe is CVE-2010-0218?
CVE-2010-0218 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0218?
Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind.