Overview
ISC BIND contains a vulnerability in the processing of the allow-query access control specifier.
Description
According to ISC: When named is running as an authoritative server for a zone and receives a query for that zone data, it first checks for allow-query acls in the zone statement, then in that view, then in global options. If none of these exist, it defaults to allowing any query (allow-query {"any"};). |
Impact
The configured acl is not correctly applied, allowing queries that the owner did not wish to allow. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Internet Systems Consortium for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2010-3615 |
Severity Metric: | 7.65 |
Date Public: | 2010-12-01 |
Date First Published: | 2010-12-01 |
Date Last Updated: | 2010-12-01 21:33 UTC |
Document Revision: | 19 |