Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2776

Опубликовано: 27 сент. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 5

Описание

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

A denial of service flaw was found in the way BIND constructed a response to a query that met certain criteria. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS request packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindWill not fix
Red Hat Enterprise Linux 5bindFixedRHSA-2016:194428.09.2016
Red Hat Enterprise Linux 5bind97FixedRHSA-2016:194528.09.2016
Red Hat Enterprise Linux 6bindFixedRHSA-2016:194428.09.2016
Red Hat Enterprise Linux 6.2 Advanced Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.5 Telco Extended Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.6 Extended Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.7 Extended Update SupportbindFixedRHSA-2016:209925.10.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1378380bind: assertion failure in buffer.c while building responses to a specifically constructed request

7.5 High

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

CVSS3: 7.5
nvd
около 9 лет назад

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

CVSS3: 7.5
debian
около 9 лет назад

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4- ...

suse-cvrf
около 9 лет назад

Security update for bind

suse-cvrf
около 9 лет назад

Security update for bind

7.5 High

CVSS3

5 Medium

CVSS2