Overview
ISC BIND named contains a vulnerability where under certain situations it could incorrectly mark zone data as insecure.
Description
According to ISC: named, acting as a DNSSEC validator, was determining if an NS RRset is insecure based on a value that could mean either that the RRset is actually insecure or that there wasn't a matching key for the RRSIG in the DNSKEY RRset when resuming from validating the DNSKEY RRset. |
Impact
Answers are marked incorrectly as insecure. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Internet Systems Consortium for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2010-3614 |
Severity Metric: | 7.65 |
Date Public: | 2010-12-01 |
Date First Published: | 2010-12-01 |
Date Last Updated: | 2010-12-01 21:33 UTC |
Document Revision: | 17 |