Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5477

Опубликовано: 28 июл. 2015
Источник: redhat
CVSS2: 5
EPSS Критический

Описание

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

A flaw was found in the way BIND handled requests for TKEY DNS resource records. A remote attacker could use this flaw to make named (functioning as an authoritative DNS server or a DNS resolver) exit unexpectedly with an assertion failure via a specially crafted DNS request packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindWill not fix
Red Hat Enterprise Linux 5bindFixedRHSA-2015:151428.07.2015
Red Hat Enterprise Linux 5bind97FixedRHSA-2015:151528.07.2015
Red Hat Enterprise Linux 6bindFixedRHSA-2015:151329.07.2015
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:007828.01.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:007828.01.2016
Red Hat Enterprise Linux 6.6 Extended Update SupportbindFixedRHSA-2016:007928.01.2016
Red Hat Enterprise Linux 7bindFixedRHSA-2015:151329.07.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-456->CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1247361bind: TKEY query handling flaw leading to denial of service

EPSS

Процентиль: 100%
0.92832
Критический

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

nvd
около 10 лет назад

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

debian
около 10 лет назад

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allo ...

suse-cvrf
около 10 лет назад

Security update for bind

suse-cvrf
около 10 лет назад

Security update for bind

EPSS

Процентиль: 100%
0.92832
Критический

5 Medium

CVSS2