named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/69568 | vdb entry |
http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories | |
http://securitytracker.com/id?1024817 | vdb entry |
http://www.isc.org/software/bind/advisories/cve-2010-3615 | vendor advisory |
http://secunia.com/advisories/42458 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/45134 | vdb entry |
http://www.vupen.com/english/advisories/2010/3102 | vdb entry vendor advisory |
http://secunia.com/advisories/42671 | third party advisory |
http://www.kb.cert.org/vuls/id/510208 | third party advisory us government resource |
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051963.html | vendor advisory |
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.622190 | vendor advisory |