← Vulnerability feed

Vulnerability record · CVE-2009-0025 · published 7 January 2009

CVE-2009-0025: Isc bind improper authentication vulnerability

Isc · Bind

BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

6.8 CVSS 2.0 Medium EPSS 6.9% · top 6.2% CWE-287 · Improper authentication
6.8CVSS 2.0 base score
6.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
66References
16 Jun 2026Last modified by NVD

Description

BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://marc.info/?l=bugtraq&m=141879471518471&w=2
http://secunia.com/advisories/33494
http://secunia.com/advisories/33546
http://secunia.com/advisories/33551
http://secunia.com/advisories/33559
http://secunia.com/advisories/33683
http://secunia.com/advisories/33882
http://secunia.com/advisories/35074
http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.asc
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.540362
http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1
http://support.apple.com/kb/HT3549
http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm
http://wiki.rpath.com/Advisories:rPSA-2009-0009
http://www.ocert.org/advisories/ocert-2008-016.html
http://www.openbsd.org/errata44.html#008_bind
http://www.securityfocus.com/archive/1/499827/100/0/threaded
http://www.securityfocus.com/archive/1/500207/100/0/threaded
http://www.securityfocus.com/archive/1/502322/100/0/threaded
http://www.securityfocus.com/bid/33151
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vmware.com/security/advisories/VMSA-2009-0004.html
http://www.vupen.com/english/advisories/2009/0043
http://www.vupen.com/english/advisories/2009/0366
http://www.vupen.com/english/advisories/2009/0904
http://www.vupen.com/english/advisories/2009/1297
https://issues.rpath.com/browse/RPL-2938
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10879
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5569
https://www.isc.org/software/bind/advisories/cve-2009-0025
https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.html
http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://marc.info/?l=bugtraq&m=141879471518471&w=2
http://secunia.com/advisories/33494
http://secunia.com/advisories/33546
http://secunia.com/advisories/33551
http://secunia.com/advisories/33559

Track CVE-2009-0025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2009-0025), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.