Overview
A flaw exists in BIND 9.7.2 through 9.7.2-P1 pertaining to how an ACL is applied.
Description
There is a flaw in BIND 9.7.2 through 9.7.2-P1 where the wrong ACL is applied. This flaw could allow access to a cache via recursion even though the ACL disallowed it. This bug is primarily a risk to operators running both authoritative and recursive DNS on the same BIND server in the same view.  | 
Impact
A loss of confidentiality in cache data exists.  | 
Solution
Upgrade to BIND 9.7.2-P2  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This document was written by Jared Allar.
Other Information
| CVE IDs: | CVE-2010-0218 | 
| Severity Metric: | 0.01 | 
| Date Public: | 2010-09-28 | 
| Date First Published: | 2010-09-30 | 
| Date Last Updated: | 2010-09-30 13:49 UTC | 
| Document Revision: | 8 |