Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5680

Опубликовано: 13 фев. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

A flaw was found in the bind9 package. This issue may allow an attacker to substantially decrease named performance by sending a specific set of queries, forcing the same name to have a large number of ECS records stored. In the worst case scenario, named can become unresponsive, leading to a Denial of Service.

Отчет

The versions of bind9 shipped with Red Hat Enterprise Linux 6, 7, 8 and 9 are not affected by this vulnerability as it doesn't contain the vulnerable code. This CVE only impacts the "-S" versions of bind9 package, which are different in code base than the ones distributed in Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 8bind9.16Not affected
Red Hat Enterprise Linux 9bindNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2264285bind9: Cleaning an ECS-enabled cache may cause excessive CPU load

EPSS

Процентиль: 29%
0.00105
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

CVSS3: 5.3
nvd
почти 2 года назад

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

msrc
больше 1 года назад

Cleaning an ECS-enabled cache may cause excessive CPU load

CVSS3: 5.3
debian
почти 2 года назад

If a resolver cache has a very large number of ECS records stored for ...

CVSS3: 5.3
github
почти 2 года назад

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

EPSS

Процентиль: 29%
0.00105
Низкий

5.3 Medium

CVSS3