Executive Summary

Informations
NameCVE-2012-1667First vendor Publication2012-06-05
VendorCveLast vendor Modification2013-04-18

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:C)
Cvss Base Score8.5Attack RangeNetwork
Cvss Impact Score7.8Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1667

CWE : Common Weakness Enumeration

idName
CWE-189Numeric Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application35

Internal Sources (Detail)

SourceUrl
APPLEhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
CONFIRMhttp://support.apple.com/kb/HT5501
http://www.isc.org/software/bind/advisories/cve-2012-1667
https://kb.isc.org/article/AA-00698
HPhttp://marc.info/?l=bugtraq&m=134132772016230&w=2
http://marc.info/?l=bugtraq&m=134132772016230&w=2
REDHAThttp://rhn.redhat.com/errata/RHSA-2012-1110.html
SECUNIAhttp://secunia.com/advisories/51096

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2013-05-10 22:36:21
  • Multiple Updates
2013-04-19 13:20:07
  • Multiple Updates