CVE Vulnerabilities

CVE-2003-0914

Published: Dec 15, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

Affected Software

NameVendorStart VersionEnd Version
BindIsc8.2.3 (including)8.2.3 (including)
BindIsc8.2.4 (including)8.2.4 (including)
BindIsc8.2.5 (including)8.2.5 (including)
BindIsc8.2.6 (including)8.2.6 (including)
BindIsc8.2.7 (including)8.2.7 (including)
BindIsc8.3.0 (including)8.3.0 (including)
BindIsc8.3.1 (including)8.3.1 (including)
BindIsc8.3.2 (including)8.3.2 (including)
BindIsc8.3.3 (including)8.3.3 (including)
BindIsc8.3.4 (including)8.3.4 (including)
BindIsc8.3.5 (including)8.3.5 (including)
BindIsc8.3.6 (including)8.3.6 (including)
BindIsc8.4 (including)8.4 (including)
BindIsc8.4.1 (including)8.4.1 (including)
NamesurferNixustandard_3.0.1 (including)standard_3.0.1 (including)
NamesurferNixusuite_3.0.1 (including)suite_3.0.1 (including)

References