Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2848

Опубликовано: 20 окт. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

A denial of service flaw was found in the way BIND handled packets with malformed options. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindWill not fix
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 5bindFixedRHSA-2016:209320.10.2016
Red Hat Enterprise Linux 5bind97FixedRHSA-2016:209420.10.2016
Red Hat Enterprise Linux 6bindFixedRHSA-2016:209320.10.2016
Red Hat Enterprise Linux 6.2 Advanced Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.5 Telco Extended Update SupportbindFixedRHSA-2016:209925.10.2016
Red Hat Enterprise Linux 6.6 Extended Update SupportbindFixedRHSA-2016:209925.10.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1385450bind: assertion failure triggered by a packet with malformed options

EPSS

Процентиль: 98%
0.51276
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

CVSS3: 7.5
nvd
почти 9 лет назад

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

CVSS3: 7.5
debian
почти 9 лет назад

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remo ...

CVSS3: 7.5
github
больше 3 лет назад

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

oracle-oval
почти 9 лет назад

ELSA-2016-2094: bind97 security update (IMPORTANT)

EPSS

Процентиль: 98%
0.51276
Средний

7.5 High

CVSS3

5 Medium

CVSS2