named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS query mechanism. Per: http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories
'Note particularly that disabling DNSSEC validation is NOT an effective workaround.' Per: http://www.isc.org/software/bind/advisories/cve-2010-3615
'This bug doesn't affect allow-recursion or allow-query-cache acls, since they are not relevant to a zone for which the server is authoritative. '
Publication date: Mon, 06 Dec 2010 19:44:00 +0000