Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2775

Опубликовано: 18 июл. 2016
Источник: redhat
CVSS3: 5.9
CVSS2: 4.3
EPSS Средний

Описание

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

It was found that the lightweight resolver protocol implementation in BIND could enter an infinite recursion and crash when asked to resolve a query name which, when combined with a search list entry, exceeds the maximum allowable length. A remote attacker could use this flaw to crash lwresd or named when using the "lwres" statement in named.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bindWill not fix
Red Hat Enterprise Linux 5bind97Will not fix
Red Hat Enterprise Linux 6bindFixedRHBA-2017:065121.03.2017
Red Hat Enterprise Linux 7bindFixedRHBA-2017:176701.08.2017
Red Hat Enterprise Linux 7.2 Extended Update SupportbindFixedRHSA-2017:253324.08.2017
Red Hat Enterprise Linux 7.3 Extended Update SupportbindFixedRHSA-2017:253324.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1357803bind: Too long query name causes segmentation fault in lwresd

EPSS

Процентиль: 97%
0.43295
Средний

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

CVSS3: 5.9
nvd
больше 9 лет назад

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

CVSS3: 5.9
debian
больше 9 лет назад

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x befo ...

CVSS3: 5.9
github
больше 3 лет назад

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

suse-cvrf
почти 9 лет назад

Security update for bind

EPSS

Процентиль: 97%
0.43295
Средний

5.9 Medium

CVSS3

4.3 Medium

CVSS2