← Vulnerability feed

Vulnerability record · CVE-2010-0290 · published 22 January 2010

CVE-2010-0290: Isc bind vulnerability

Isc · Bind

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.

4.0 CVSS 2.0 Medium EPSS 6.8% · top 6.2%
4.0CVSS 2.0 base score
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.

AV:N/AC:H/Au:N/C:N/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
http://marc.info/?l=oss-security&m=126393609503704&w=2
http://marc.info/?l=oss-security&m=126399602810086&w=2
http://secunia.com/advisories/38219 Vendor Advisory
http://secunia.com/advisories/38240 Vendor Advisory
http://secunia.com/advisories/40086
http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018
http://www.debian.org/security/2010/dsa-2054
http://www.mandriva.com/security/advisories?name=MDVSA-2010:021
http://www.ubuntu.com/usn/USN-888-1
http://www.vupen.com/english/advisories/2010/0176 Vendor Advisory
http://www.vupen.com/english/advisories/2010/0622
http://www.vupen.com/english/advisories/2010/1352
https://bugzilla.redhat.com/show_bug.cgi?id=554851
https://bugzilla.redhat.com/show_bug.cgi?id=557121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6815
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8884
https://rhn.redhat.com/errata/RHSA-2010-0062.html
https://www.isc.org/advisories/CVE-2009-4022v6 Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
http://marc.info/?l=oss-security&m=126393609503704&w=2
http://marc.info/?l=oss-security&m=126399602810086&w=2
http://secunia.com/advisories/38219 Vendor Advisory
http://secunia.com/advisories/38240 Vendor Advisory
http://secunia.com/advisories/40086
http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018
http://www.debian.org/security/2010/dsa-2054
http://www.mandriva.com/security/advisories?name=MDVSA-2010:021
http://www.ubuntu.com/usn/USN-888-1
http://www.vupen.com/english/advisories/2010/0176 Vendor Advisory
http://www.vupen.com/english/advisories/2010/0622
http://www.vupen.com/english/advisories/2010/1352
https://bugzilla.redhat.com/show_bug.cgi?id=554851
https://bugzilla.redhat.com/show_bug.cgi?id=557121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6815
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8884
https://rhn.redhat.com/errata/RHSA-2010-0062.html
https://www.isc.org/advisories/CVE-2009-4022v6 Vendor Advisory

Track CVE-2010-0290 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2010-0290), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.