Описание
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
A denial of service flaw was found in the way BIND parsed signature records for DNAME records. By sending a specially crafted query, a remote attacker could use this flaw to cause named to crash.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | bind | Will not fix | ||
Red Hat Enterprise Linux 5 | bind97 | Fixed | RHSA-2016:0458 | 16.03.2016 |
Red Hat Enterprise Linux 5 | bind | Fixed | RHSA-2016:0459 | 16.03.2016 |
Red Hat Enterprise Linux 6 | bind | Fixed | RHSA-2016:0459 | 16.03.2016 |
Red Hat Enterprise Linux 6.2 Advanced Update Support | bind | Fixed | RHSA-2016:0601 | 06.04.2016 |
Red Hat Enterprise Linux 6.4 Advanced Update Support | bind | Fixed | RHSA-2016:0562 | 31.03.2016 |
Red Hat Enterprise Linux 6.5 Advanced Update Support | bind | Fixed | RHSA-2016:0562 | 31.03.2016 |
Red Hat Enterprise Linux 6.6 Extended Update Support | bind | Fixed | RHSA-2016:0562 | 31.03.2016 |
Red Hat Enterprise Linux 7 | bind | Fixed | RHSA-2016:0459 | 16.03.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allo ...
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Уязвимость сервера DNS BIND, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2