ISC BIND 9是ISC组织的一个域名系统软件。 ISC BIND 9 9.11.0版本至9.16.50版本、9.18.0版本至9.18.39版本、9.20.0版本至9.20.13版本、9.21.0版本至9.21.12版本、9.11.3-S1版本至9.16.50-S1版本、9.18.11-S1版本至9.18.39-S1版本和9.20.9-S1版本至9.20.13-S1版本存在安全漏洞,该漏洞源于接受应答记录时过于宽松,可能导致缓存中注入伪造数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | POC CVE-2025-40778: Cache Poisoning BIND 9 👾 | https://github.com/nehkark/CVE-2025-40778 | POC Details |
| 2 | Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records. | https://github.com/sirbuvladste/BIND-9-Cache-Poisoning-PoC---CVE-2025-40778 | POC Details |
| 3 | Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping, and remediation via hardened Unbound (DoT) on Arch Linux. | https://github.com/nicholasC03/DNS-Poisoning-Triage-Lab | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-40780 | 8.6 HIGH | Cache poisoning due to weak PRNG |
| CVE-2025-8677 | 7.5 HIGH | Resource exhaustion via malformed DNSKEY handling |
No comments yet