Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1667

Опубликовано: 04 июн. 2012
Источник: redhat
CVSS2: 6.4
EPSS Средний

Описание

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3bindWill not fix
Red Hat Enterprise Linux 4 Extended Lifecycle SupportbindFixedRHSA-2012:111023.07.2012
Red Hat Enterprise Linux 5bindFixedRHSA-2012:071607.06.2012
Red Hat Enterprise Linux 5bind97FixedRHSA-2012:071707.06.2012
Red Hat Enterprise Linux 6bindFixedRHSA-2012:071607.06.2012

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=828078bind: handling of zero length rdata can cause named to terminate unexpectedly

EPSS

Процентиль: 97%
0.39738
Средний

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.

nvd
около 13 лет назад

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.

debian
около 13 лет назад

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9. ...

github
больше 3 лет назад

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.

oracle-oval
около 13 лет назад

ELSA-2012-0717: bind97 security update (IMPORTANT)

EPSS

Процентиль: 97%
0.39738
Средний

6.4 Medium

CVSS2