Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8000

Опубликовано: 15 дек. 2015
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.

A denial of service flaw was found in the way BIND processed certain records with malformed class attributes. A remote attacker could use this flaw to send a query to request a cached record with a malformed class attribute that would cause named functioning as an authoritative or recursive server to crash. Note: This issue affects authoritative servers as well as recursive servers, however authoritative servers are at limited risk if they perform authentication when making recursive queries to resolve addresses for servers listed in NS RRSETs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindWill not fix
Red Hat Enterprise Linux 5bindFixedRHSA-2015:265616.12.2015
Red Hat Enterprise Linux 5bind97FixedRHSA-2015:265816.12.2015
Red Hat Enterprise Linux 6bindFixedRHSA-2015:265516.12.2015
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:007828.01.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:007828.01.2016
Red Hat Enterprise Linux 6.6 Extended Update SupportbindFixedRHSA-2016:007928.01.2016
Red Hat Enterprise Linux 7bindFixedRHSA-2015:265516.12.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1291176bind: responses with a malformed class attribute can trigger an assertion failure in db.c

EPSS

Процентиль: 98%
0.54087
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 9 лет назад

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.

nvd
больше 9 лет назад

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.

debian
больше 9 лет назад

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3 ...

suse-cvrf
больше 9 лет назад

Security update for bind

suse-cvrf
больше 9 лет назад

Security update for bind

EPSS

Процентиль: 98%
0.54087
Средний

4.3 Medium

CVSS2