Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5722

Опубликовано: 02 сент. 2015
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

A denial of service flaw was found in the way BIND parsed certain malformed DNSSEC keys. A remote attacker could use this flaw to send a specially crafted DNS query (for example, a query requiring a response from a zone containing a deliberately malformed key) that would cause named functioning as a validating resolver to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindAffected
Red Hat Enterprise Linux 5bindFixedRHSA-2015:170603.09.2015
Red Hat Enterprise Linux 5bind97FixedRHSA-2015:170703.09.2015
Red Hat Enterprise Linux 6bindFixedRHSA-2015:170503.09.2015
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:007828.01.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:007828.01.2016
Red Hat Enterprise Linux 6.6 Extended Update SupportbindFixedRHSA-2016:007928.01.2016
Red Hat Enterprise Linux 7bindFixedRHSA-2015:170503.09.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1259087bind: malformed DNSSEC key failed assertion denial of service

EPSS

Процентиль: 98%
0.50782
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

nvd
почти 10 лет назад

buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

debian
почти 10 лет назад

buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9. ...

suse-cvrf
почти 10 лет назад

Security update for bind

suse-cvrf
почти 10 лет назад

Security update for bind

EPSS

Процентиль: 98%
0.50782
Средний

5 Medium

CVSS2