FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2003-0914

This CVE name corresponds to:

Entered Topic
2003-12-12 bind8 negative cache poison attack

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2003-0914
Phase Assigned(20031104)

Description

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

References

Source Reference
ENGARDE ESA-20031126-031
IMMUNIX IMNX-2003-7+-024-01
FREEBSD FreeBSD-SA-03:19.bind
SUSE SuSE-SA:2003:047
NETBSD NetBSD-SA2003-018
DEBIAN DSA-409
SUNALERT 57434
TRUSTIX 2003-0044
SCO CSSA-2003-SCO.33
SCO CSSA-2004-003.0
IBM MSS-OAR-E01-2003.1524
CERT-VN VU#734644
OVAL oval:org.mitre.oval:def:2011
SECUNIA 10542