CVE-2010-3762

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/10/2010
Last modified:
11/04/2025

Description

ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:*:p2:*:*:*:*:*:* 9.7.2 (including)