Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3080

Опубликовано: 21 сент. 2022
Источник: redhat
CVSS3: 7.5

Описание

By sending specific queries to the resolver, an attacker can cause named to crash.

A flaw was found in the Bind package, where the resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to 0 and there is a stale CNAME in the cache for an incoming query. By sending specific queries to the resolver, an attacker can cause named to crash.

Отчет

This issue affects versions 9.16.14 and higher of the Bind package. Therefore Red Hat Enterprise Linux 6 and 7 are not impacted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Enterprise Linux 8bind9.16FixedRHSA-2022:678104.10.2022
Red Hat Enterprise Linux 9bindFixedRHSA-2022:676303.10.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2128600bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

By sending specific queries to the resolver, an attacker can cause named to crash.

CVSS3: 7.5
nvd
больше 2 лет назад

By sending specific queries to the resolver, an attacker can cause named to crash.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

By sending specific queries to the resolver, an attacker can cause nam ...

CVSS3: 7.5
github
больше 2 лет назад

By sending specific queries to the resolver, an attacker can cause named to crash.

7.5 High

CVSS3