Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8864

Опубликовано: 01 нояб. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

A denial of service flaw was found in the way BIND handled responses containing a DNAME answer. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4bindWill not fix
Red Hat Enterprise Linux 5bindFixedRHSA-2016:214102.11.2016
Red Hat Enterprise Linux 5bind97FixedRHSA-2016:214202.11.2016
Red Hat Enterprise Linux 6bindFixedRHSA-2016:214102.11.2016
Red Hat Enterprise Linux 6.2 Advanced Update SupportbindFixedRHSA-2016:287106.12.2016
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2016:287106.12.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2016:287106.12.2016
Red Hat Enterprise Linux 6.5 Telco Extended Update SupportbindFixedRHSA-2016:287106.12.2016
Red Hat Enterprise Linux 6.6 Advanced Update SupportbindFixedRHSA-2016:287106.12.2016
Red Hat Enterprise Linux 6.6 Telco Extended Update SupportbindFixedRHSA-2016:287106.12.2016

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1389652bind: assertion failure while handling responses containing a DNAME answer

EPSS

Процентиль: 97%
0.4301
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

CVSS3: 7.5
nvd
почти 9 лет назад

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

CVSS3: 7.5
debian
почти 9 лет назад

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9. ...

suse-cvrf
почти 9 лет назад

Security update for bind

suse-cvrf
почти 9 лет назад

Security update for bind

EPSS

Процентиль: 97%
0.4301
Средний

7.5 High

CVSS3

5 Medium

CVSS2