CVE-2006-0527

BIND 4 and BIND 8 - Remote Privilege Escalation via DNS Cache Corruption

Title source: llm
STIX 2.1

Description

BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.

References (13)

Core 13
Core References
Various Sources vendor-advisory x_refsource_hp
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00595837
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0399
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015606
Various Sources mailing-list x_refsource_vim
http://attrition.org/pipermail/vim/2006-February/000551.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/22888
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/425083/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18690
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/438
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/748
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015551
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16455
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24414

Scores

EPSS 0.0709
EPSS Percentile 91.6%

Details

CWE
CWE-264
Status published
Products (2)
isc/bind 4
isc/bind 8
Published Feb 02, 2006
Tracked Since Feb 18, 2026