CVE-2003-0914

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/12/2003
Last modified:
03/04/2025

Description

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:8.2.3:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.2.4:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.2.5:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.2.6:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.2.7:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.0:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.1:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.2:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.3:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.4:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.5:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.3.6:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.4:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:nixu:namesurfer:standard_3.0.1:*:*:*:*:*:*:*