Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
References
Link Providers
ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt cve-icon cve-icon
http://aix.software.ibm.com/aix/efixes/security/bind9_advisory.asc cve-icon cve-icon
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2010/000082.html cve-icon cve-icon
http://osvdb.org/60493 cve-icon cve-icon
http://secunia.com/advisories/37426 cve-icon cve-icon
http://secunia.com/advisories/37491 cve-icon cve-icon
http://secunia.com/advisories/38219 cve-icon cve-icon
http://secunia.com/advisories/38240 cve-icon cve-icon
http://secunia.com/advisories/38794 cve-icon cve-icon
http://secunia.com/advisories/38834 cve-icon cve-icon
http://secunia.com/advisories/39334 cve-icon cve-icon
http://secunia.com/advisories/40730 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021660.1-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1 cve-icon cve-icon
http://support.apple.com/kb/HT5002 cve-icon cve-icon
http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018 cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=isg1IZ68597 cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=isg1IZ71667 cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=isg1IZ71774 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/418861 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:304 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2009/11/24/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2009/11/24/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2009/11/24/8 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2009-1620.html cve-icon cve-icon
http://www.securityfocus.com/bid/37118 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-888-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3335 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0176 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0528 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0622 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=538744 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/54416 cve-icon cve-icon
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-3152 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-4022 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10821 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11745 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7261 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7459 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-4022 cve-icon
https://www.isc.org/advisories/CVE-2009-4022v6 cve-icon cve-icon
https://www.isc.org/advisories/CVE2009-4022 cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01172.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01188.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2009-11-25T16:00:00

Updated: 2024-08-07T06:45:50.986Z

Reserved: 2009-11-20T00:00:00

Link: CVE-2009-4022

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-11-25T16:30:00.937

Modified: 2017-09-19T01:29:54.000

Link: CVE-2009-4022

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-11-23T00:00:00Z

Links: CVE-2009-4022 - Bugzilla