CVE-2009-4022
Summary
| CVE | CVE-2009-4022 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-25 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. |
Risk And Classification
Primary CVSS: v2.0 2.6 from [email protected]
AV:N/AC:H/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Isc | Bind | 9.0 | All | All | All |
| Application | Isc | Bind | 9.0.0 | rc1 | All | All |
| Application | Isc | Bind | 9.0.0 | rc2 | All | All |
| Application | Isc | Bind | 9.0.0 | rc3 | All | All |
| Application | Isc | Bind | 9.0.0 | rc4 | All | All |
| Application | Isc | Bind | 9.0.0 | rc5 | All | All |
| Application | Isc | Bind | 9.0.0 | rc6 | All | All |
| Application | Isc | Bind | 9.0.1 | All | All | All |
| Application | Isc | Bind | 9.0.1 | rc1 | All | All |
| Application | Isc | Bind | 9.0.1 | rc2 | All | All |
| Application | Isc | Bind | 9.1 | All | All | All |
| Application | Isc | Bind | 9.1.0 | rc1 | All | All |
| Application | Isc | Bind | 9.1.1 | All | All | All |
| Application | Isc | Bind | 9.1.1 | rc1 | All | All |
| Application | Isc | Bind | 9.1.1 | rc2 | All | All |
| Application | Isc | Bind | 9.1.1 | rc3 | All | All |
| Application | Isc | Bind | 9.1.1 | rc4 | All | All |
| Application | Isc | Bind | 9.1.1 | rc5 | All | All |
| Application | Isc | Bind | 9.1.1 | rc6 | All | All |
| Application | Isc | Bind | 9.1.1 | rc7 | All | All |
| Application | Isc | Bind | 9.1.2 | All | All | All |
| Application | Isc | Bind | 9.1.2 | rc1 | All | All |
| Application | Isc | Bind | 9.1.3 | All | All | All |
| Application | Isc | Bind | 9.1.3 | rc1 | All | All |
| Application | Isc | Bind | 9.1.3 | rc2 | All | All |
| Application | Isc | Bind | 9.1.3 | rc3 | All | All |
| Application | Isc | Bind | 9.2 | All | All | All |
| Application | Isc | Bind | 9.2.0 | All | All | All |
| Application | Isc | Bind | 9.2.0 | a1 | All | All |
| Application | Isc | Bind | 9.2.0 | a2 | All | All |
| Application | Isc | Bind | 9.2.0 | a3 | All | All |
| Application | Isc | Bind | 9.2.0 | b1 | All | All |
| Application | Isc | Bind | 9.2.0 | b2 | All | All |
| Application | Isc | Bind | 9.2.0 | rc1 | All | All |
| Application | Isc | Bind | 9.2.0 | rc10 | All | All |
| Application | Isc | Bind | 9.2.0 | rc2 | All | All |
| Application | Isc | Bind | 9.2.0 | rc3 | All | All |
| Application | Isc | Bind | 9.2.0 | rc4 | All | All |
| Application | Isc | Bind | 9.2.0 | rc5 | All | All |
| Application | Isc | Bind | 9.2.0 | rc6 | All | All |
| Application | Isc | Bind | 9.2.0 | rc7 | All | All |
| Application | Isc | Bind | 9.2.0 | rc8 | All | All |
| Application | Isc | Bind | 9.2.0 | rc9 | All | All |
| Application | Isc | Bind | 9.2.1 | All | All | All |
| Application | Isc | Bind | 9.2.1 | rc1 | All | All |
| Application | Isc | Bind | 9.2.1 | rc2 | All | All |
| Application | Isc | Bind | 9.2.2 | All | All | All |
| Application | Isc | Bind | 9.2.2 | p2 | All | All |
| Application | Isc | Bind | 9.2.2 | p3 | All | All |
| Application | Isc | Bind | 9.2.2 | rc1 | All | All |
| Application | Isc | Bind | 9.2.3 | All | All | All |
| Application | Isc | Bind | 9.2.3 | rc1 | All | All |
| Application | Isc | Bind | 9.2.3 | rc2 | All | All |
| Application | Isc | Bind | 9.2.3 | rc3 | All | All |
| Application | Isc | Bind | 9.2.3 | rc4 | All | All |
| Application | Isc | Bind | 9.2.4 | All | All | All |
| Application | Isc | Bind | 9.2.4 | rc2 | All | All |
| Application | Isc | Bind | 9.2.4 | rc3 | All | All |
| Application | Isc | Bind | 9.2.4 | rc4 | All | All |
| Application | Isc | Bind | 9.2.4 | rc5 | All | All |
| Application | Isc | Bind | 9.2.4 | rc6 | All | All |
| Application | Isc | Bind | 9.2.4 | rc7 | All | All |
| Application | Isc | Bind | 9.2.4 | rc8 | All | All |
| Application | Isc | Bind | 9.2.5 | All | All | All |
| Application | Isc | Bind | 9.2.5 | b2 | All | All |
| Application | Isc | Bind | 9.2.5 | rc1 | All | All |
| Application | Isc | Bind | 9.2.6 | All | All | All |
| Application | Isc | Bind | 9.2.6 | rc1 | All | All |
| Application | Isc | Bind | 9.2.7 | All | All | All |
| Application | Isc | Bind | 9.2.7 | rc1 | All | All |
| Application | Isc | Bind | 9.2.7 | rc2 | All | All |
| Application | Isc | Bind | 9.2.7 | rc3 | All | All |
| Application | Isc | Bind | 9.2.8 | All | All | All |
| Application | Isc | Bind | 9.2.9 | All | All | All |
| Application | Isc | Bind | 9.2.9 | rc1 | All | All |
| Application | Isc | Bind | 9.3 | All | All | All |
| Application | Isc | Bind | 9.3.0 | All | All | All |
| Application | Isc | Bind | 9.3.0 | b2 | All | All |
| Application | Isc | Bind | 9.3.0 | b3 | All | All |
| Application | Isc | Bind | 9.3.0 | b4 | All | All |
| Application | Isc | Bind | 9.3.0 | rc1 | All | All |
| Application | Isc | Bind | 9.3.0 | rc2 | All | All |
| Application | Isc | Bind | 9.3.0 | rc3 | All | All |
| Application | Isc | Bind | 9.3.0 | rc4 | All | All |
| Application | Isc | Bind | 9.3.1 | All | All | All |
| Application | Isc | Bind | 9.3.1 | b2 | All | All |
| Application | Isc | Bind | 9.3.1 | rc1 | All | All |
| Application | Isc | Bind | 9.3.2 | All | All | All |
| Application | Isc | Bind | 9.3.2 | rc1 | All | All |
| Application | Isc | Bind | 9.3.3 | All | All | All |
| Application | Isc | Bind | 9.3.3 | rc1 | All | All |
| Application | Isc | Bind | 9.3.3 | rc2 | All | All |
| Application | Isc | Bind | 9.3.3 | rc3 | All | All |
| Application | Isc | Bind | 9.3.4 | All | All | All |
| Application | Isc | Bind | 9.3.5 | All | All | All |
| Application | Isc | Bind | 9.3.5 | rc1 | All | All |
| Application | Isc | Bind | 9.3.5 | rc2 | All | All |
| Application | Isc | Bind | 9.3.6 | All | All | All |
| Application | Isc | Bind | 9.3.6 | rc1 | All | All |
| Application | Isc | Bind | 9.4.0 | All | All | All |
| Application | Isc | Bind | 9.4.0 | a1 | All | All |
| Application | Isc | Bind | 9.4.0 | a2 | All | All |
| Application | Isc | Bind | 9.4.0 | a3 | All | All |
| Application | Isc | Bind | 9.4.0 | a4 | All | All |
| Application | Isc | Bind | 9.4.0 | a5 | All | All |
| Application | Isc | Bind | 9.4.0 | a6 | All | All |
| Application | Isc | Bind | 9.4.0 | b1 | All | All |
| Application | Isc | Bind | 9.4.0 | b2 | All | All |
| Application | Isc | Bind | 9.4.0 | b3 | All | All |
| Application | Isc | Bind | 9.4.0 | b4 | All | All |
| Application | Isc | Bind | 9.4.0 | rc1 | All | All |
| Application | Isc | Bind | 9.4.0 | rc2 | All | All |
| Application | Isc | Bind | 9.4.1 | All | All | All |
| Application | Isc | Bind | 9.4.2 | All | All | All |
| Application | Isc | Bind | 9.4.2 | rc1 | All | All |
| Application | Isc | Bind | 9.4.2 | rc2 | All | All |
| Application | Isc | Bind | 9.4.3 | All | All | All |
| Application | Isc | Bind | 9.4.3 | b1 | All | All |
| Application | Isc | Bind | 9.4.3 | b2 | All | All |
| Application | Isc | Bind | 9.4.3 | b3 | All | All |
| Application | Isc | Bind | 9.4.3 | p1 | All | All |
| Application | Isc | Bind | 9.4.3 | p2 | All | All |
| Application | Isc | Bind | 9.4.3 | p3 | All | All |
| Application | Isc | Bind | 9.4.3 | rc1 | All | All |
| Application | Isc | Bind | 9.5.0 | All | All | All |
| Application | Isc | Bind | 9.5.0 | a1 | All | All |
| Application | Isc | Bind | 9.5.0 | a2 | All | All |
| Application | Isc | Bind | 9.5.0 | a3 | All | All |
| Application | Isc | Bind | 9.5.0 | a4 | All | All |
| Application | Isc | Bind | 9.5.0 | a5 | All | All |
| Application | Isc | Bind | 9.5.0 | a6 | All | All |
| Application | Isc | Bind | 9.5.0 | a7 | All | All |
| Application | Isc | Bind | 9.5.0 | b1 | All | All |
| Application | Isc | Bind | 9.5.0 | b2 | All | All |
| Application | Isc | Bind | 9.5.0 | b3 | All | All |
| Application | Isc | Bind | 9.5.0 | p1 | All | All |
| Application | Isc | Bind | 9.5.0 | p2 | All | All |
| Application | Isc | Bind | 9.5.0 | p2_w1 | All | All |
| Application | Isc | Bind | 9.5.0 | p2_w2 | All | All |
| Application | Isc | Bind | 9.5.0 | rc1 | All | All |
| Application | Isc | Bind | 9.5.1 | All | All | All |
| Application | Isc | Bind | 9.5.1 | b1 | All | All |
| Application | Isc | Bind | 9.5.1 | b2 | All | All |
| Application | Isc | Bind | 9.5.1 | b3 | All | All |
| Application | Isc | Bind | 9.5.1 | rc1 | All | All |
| Application | Isc | Bind | 9.5.1 | rc2 | All | All |
| Application | Isc | Bind | 9.5.2 | All | All | All |
| Application | Isc | Bind | 9.5.2 | b1 | All | All |
| Application | Isc | Bind | 9.5.2 | rc1 | All | All |
| Application | Isc | Bind | 9.6.0 | All | All | All |
| Application | Isc | Bind | 9.6.0 | a1 | All | All |
| Application | Isc | Bind | 9.6.0 | b1 | All | All |
| Application | Isc | Bind | 9.6.0 | p1 | All | All |
| Application | Isc | Bind | 9.6.0 | rc1 | All | All |
| Application | Isc | Bind | 9.6.0 | rc2 | All | All |
| Application | Isc | Bind | 9.6.1 | All | All | All |
| Application | Isc | Bind | 9.6.1 | b1 | All | All |
| Application | Isc | Bind | 9.6.1 | p1 | All | All |
| Application | Isc | Bind | 9.6.1 | rc1 | All | All |
| Application | Isc | Bind | 9.7.0 | All | All | All |
| Application | Isc | Bind | 9.7.0 | a1 | All | All |
| Application | Isc | Bind | 9.7.0 | a2 | All | All |
| Application | Isc | Bind | 9.7.0 | a3 | All | All |
| Application | Isc | Bind | 9.7.0 | b1 | All | All |
| Application | Isc | Bind | 9.7.0 | b2 | All | All |
| Application | Isc | Bind | 9.7.0 | b3 | All | All |
| Application | Isc | Bind | 9.7.0 | p1 | All | All |
| Application | Isc | Bind | 9.7.0 | rc1 | All | All |
| Application | Isc | Bind | 9.7.0 | rc2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE request: BIND 9 bug involving DNSSEC and the additional section | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| ISC BIND 9 DNSSEC Query Response Additional Section Remote Cache Poisoning Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM AIX BIND DNSSEC Cache Poisoning Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| [SECURITY] Fedora 11 Update: bind-9.6.1-7.P2.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Sun Solaris BIND DNS Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| USN-888-1: Bind vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Oops! - ISC | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | Vendor Advisory |
| VMware vMA Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 12 Update: bind-9.6.1-13.P2.fc12 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| oss-security - a new bind issue | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20564.www2.hpe.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support / Security / Advisories / / MDVSA-2009:304 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| UnixWare update for bind - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ISC BIND DNSSEC CNAME / DNAME and NXDOMAIN Cache Poisoning Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | |
| osvdb.org/60493 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| APPLE-SA-2011-10-12-3 OS X Lion v10.7.2 and Security Update 2011-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Ubuntu update for bind9 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IZ68597: POTENTIAL SECURITY ISSUE. APPLIES TO AIX 6100-04 | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| US-CERT Vulnerability Note VU#418861 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| IZ71667: POTENTIAL SECURITY ISSUE. APPLIES TO AIX 6100-03 | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| About the security content of OS X Lion v10.7.2 and Security Update 2011-006 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Advisories:rPSA-2010-0018 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| aix.software.ibm.com/aix/efixes/security/bind9_advisory.asc | af854a3a-2127-422b-91ae-364da2661108 | aix.software.ibm.com | |
| issues.rpath.com/browse/RPL-3152 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [Security-announce] VMSA-2010-0004 ESX Service Console and vMA third party updates | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | |
| oss-security - Re: a new bind issue | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| VMware ESX Server 4 Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Bug 538744 – CVE-2009-4022 bind: cache poisoning using not validated DNSSEC responses | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| ISC BIND DNSSEC Cache Poisoning Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| BIND 9 Cache Update from Additional Section (updated 19Jan2010) | Internet Systems Consortium | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | Vendor Advisory |
| IZ71774: POTENTIAL SECURITY ISSUE. APPLIES TO AIX 6100-02 | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.