Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-38177

Опубликовано: 21 сент. 2022
Источник: redhat
CVSS3: 7.5

Описание

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

A flaw was found in the Bind package. By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak, resulting in crashing the program.

Отчет

This flaw affects versions 9.8.4 -> 9.16.32 of the Bind package, therefore Red Hat Enterprise Linux 6 is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Enterprise Linux 7bindFixedRHSA-2022:676503.10.2022
Red Hat Enterprise Linux 8bindFixedRHSA-2022:677804.10.2022
Red Hat Enterprise Linux 8bind9.16FixedRHSA-2022:678104.10.2022
Red Hat Enterprise Linux 8bindFixedRHSA-2022:677804.10.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsbindFixedRHSA-2022:676403.10.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportbindFixedRHSA-2022:678004.10.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportbindFixedRHSA-2022:677904.10.2022
Red Hat Enterprise Linux 9bindFixedRHSA-2022:676303.10.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2128601bind: memory leak in ECDSA DNSSEC verification code

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

CVSS3: 7.5
nvd
больше 2 лет назад

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

By spoofing the target resolver with responses that have a malformed E ...

CVSS3: 7.5
github
больше 2 лет назад

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

7.5 High

CVSS3