Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3080

Опубликовано: 21 сент. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

By sending specific queries to the resolver, an attacker can cause named to crash.

A flaw was found in the Bind package, where the resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to 0 and there is a stale CNAME in the cache for an incoming query. By sending specific queries to the resolver, an attacker can cause named to crash.

Отчет

This issue affects versions 9.16.14 and higher of the Bind package. Therefore Red Hat Enterprise Linux 6 and 7 are not impacted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Enterprise Linux 8bind9.16FixedRHSA-2022:678104.10.2022
Red Hat Enterprise Linux 9bindFixedRHSA-2022:676303.10.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2128600bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

By sending specific queries to the resolver, an attacker can cause named to crash.

CVSS3: 7.5
nvd
почти 3 года назад

By sending specific queries to the resolver, an attacker can cause named to crash.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 3 года назад

By sending specific queries to the resolver, an attacker can cause nam ...

CVSS3: 7.5
github
почти 3 года назад

By sending specific queries to the resolver, an attacker can cause named to crash.

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3