Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0667

Опубликовано: 16 мар. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

An assertion check flaw was found in BIND, with a refactoration of recursive client code that introduced a "backstop lifetime timer." While BIND processes a request for a DS record that needs to be forwarded, it waits until this processing is complete or until the backstop lifetime timer has timed out. As a result of this timeout, the resume_dslookup() function is called, which does not test whether the fetch has shut down previously. This issue triggers an assertion failure, which could cause the BIND process to terminate.

Отчет

This flaw only affects BIND-9.18.0, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 8bind9.16Not affected
Red Hat Enterprise Linux 9bindNot affected
Red Hat Enterprise Linux 9dhcpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2064515bind: When chasing DS records, a timed-out or artificially delayed fetch could cause 'named' to crash while resuming a DS lookup

EPSS

Процентиль: 71%
0.00694
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

CVSS3: 7.5
nvd
больше 3 лет назад

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

CVSS3: 7.5
debian
больше 3 лет назад

When the vulnerability is triggered the BIND process will exit. BIND 9 ...

CVSS3: 7.5
github
больше 3 лет назад

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость сервера DNS BIND, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.00694
Низкий

7.5 High

CVSS3