Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1286

Опубликовано: 09 мар. 2016
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

A denial of service flaw was found in the way BIND parsed signature records for DNAME records. By sending a specially crafted query, a remote attacker could use this flaw to cause named to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindWill not fix
Red Hat Enterprise Linux 5bind97FixedRHSA-2016:045816.03.2016
Red Hat Enterprise Linux 5bindFixedRHSA-2016:045916.03.2016
Red Hat Enterprise Linux 6bindFixedRHSA-2016:045916.03.2016
Red Hat Enterprise Linux 6.2 Advanced Update SupportbindFixedRHSA-2016:060106.04.2016
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:056231.03.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:056231.03.2016
Red Hat Enterprise Linux 6.6 Extended Update SupportbindFixedRHSA-2016:056231.03.2016
Red Hat Enterprise Linux 7bindFixedRHSA-2016:045916.03.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1315680bind: malformed signature records for DNAME records can trigger assertion failure

EPSS

Процентиль: 98%
0.54992
Средний

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 9 лет назад

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

CVSS3: 8.6
nvd
больше 9 лет назад

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

CVSS3: 8.6
debian
больше 9 лет назад

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allo ...

CVSS3: 8.6
github
больше 3 лет назад

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

fstec
больше 9 лет назад

Уязвимость сервера DNS BIND, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.54992
Средний

5 Medium

CVSS2