Vulnerability Note VU#510208
ISC BIND named allow-query vulnerability
Overview
ISC BIND contains a vulnerability in the processing of the allow-query access control specifier.
Description
According to ISC: When named is running as an authoritative server for a zone and receives a query for that zone data, it first checks for allow-query acls in the zone statement, then in that view, then in global options. If none of these exist, it defaults to allowing any query (allow-query {"any"};). |
Impact
The configured acl is not correctly applied, allowing queries that the owner did not wish to allow. |
Solution
Apply an update |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Internet Systems Consortium | Affected | - | 01 Dec 2010 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- https://www.isc.org/software/bind/advisories/cve-2010-3615
- http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories
Credit
Thanks to Internet Systems Consortium for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2010-3615
- Date Public: 01 Dec 2010
- Date First Published: 01 Dec 2010
- Date Last Updated: 01 Dec 2010
- Severity Metric: 7.65
- Document Revision: 19
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.