Логотип exploitDog
bind:"CVE-2022-3924" OR bind:"CVE-2022-2795" OR bind:"CVE-2022-3094" OR bind:"CVE-2022-3736"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-3924" OR bind:"CVE-2022-2795" OR bind:"CVE-2022-3094" OR bind:"CVE-2022-3736"

Количество 41

Количество 41

ubuntu логотип

CVE-2022-3736

около 3 лет назад

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3736

около 3 лет назад

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-3736

около 3 лет назад

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-3736

около 3 лет назад

named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-3736

около 3 лет назад

BIND 9 resolver can crash when stale cache and stale answers are enabl ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-3094

около 3 лет назад

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3094

около 3 лет назад

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3094

около 3 лет назад

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-3094

около 3 лет назад

An UPDATE message flood may cause named to exhaust all available memory

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-3094

около 3 лет назад

Sending a flood of dynamic DNS updates may cause `named` to allocate l ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3729-1

больше 3 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3682-1

больше 3 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3499-1

больше 3 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3767-1

больше 3 лет назад

Recommended update for bind

EPSS: Низкий
github логотип

GHSA-5v6f-5gpq-2628

около 3 лет назад

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-07832

около 3 лет назад

Уязвимость сервера DNS BIND, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0427-1

почти 3 года назад

Security update for bind

EPSS: Низкий
github логотип

GHSA-8f7f-g9cj-hq6g

около 3 лет назад

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7177

около 2 лет назад

ELSA-2023-7177: bind security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2023-00580

около 3 лет назад

Уязвимость компонента named сервера DNS BIND, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-3736

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-3736

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3736

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2022-3736

named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3736

BIND 9 resolver can crash when stale cache and stale answers are enabl ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-3094

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-3094

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-3094

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of

CVSS3: 7.5
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2022-3094

An UPDATE message flood may cause named to exhaust all available memory

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-3094

Sending a flood of dynamic DNS updates may cause `named` to allocate l ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3729-1

Security update for bind

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3682-1

Security update for bind

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3499-1

Security update for bind

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3767-1

Recommended update for bind

больше 3 лет назад
github логотип
GHSA-5v6f-5gpq-2628

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-07832

Уязвимость сервера DNS BIND, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0427-1

Security update for bind

1%
Низкий
почти 3 года назад
github логотип
GHSA-8f7f-g9cj-hq6g

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2023-7177

ELSA-2023-7177: bind security update (MODERATE)

около 2 лет назад
fstec логотип
BDU:2023-00580

Уязвимость компонента named сервера DNS BIND, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу