Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 41

Количество 41

oracle-oval логотип

ELSA-2023-2792

около 3 лет назад

ELSA-2023-2792: bind9.16 security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2261

около 3 лет назад

ELSA-2023-2261: bind security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0341-1

больше 3 лет назад

Security update for bind

EPSS: Низкий
ubuntu логотип

CVE-2022-3924

больше 3 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-3924

больше 3 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2022-3924

больше 3 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2022-3924

больше 3 лет назад

named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2022-3924

больше 3 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` ...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-29px-hvx8-j7xf

больше 3 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2023-07833

больше 3 лет назад

Уязвимость сервера DNS BIND, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2022-2795

почти 4 года назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-2795

почти 4 года назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-2795

почти 4 года назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2022-2795

почти 4 года назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-2795

почти 4 года назад

By flooding the target resolver with queries exploiting this flaw an a ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9mq2-v988-m7mr

почти 4 года назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-3002

около 3 лет назад

ELSA-2023-3002: bind security and bug fix update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2022-06124

почти 4 года назад

Уязвимость сервера DNS BIND, связанная с неправильным управлением внутренними ресурсами, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании» (DoS)

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3500-1

больше 3 лет назад

Security update for bind

EPSS: Низкий
oracle-oval логотип

ELSA-2023-0402

больше 3 лет назад

ELSA-2023-0402: bind security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2023-2792

ELSA-2023-2792: bind9.16 security and bug fix update (MODERATE)

около 3 лет назад
oracle-oval логотип
ELSA-2023-2261

ELSA-2023-2261: bind security and bug fix update (MODERATE)

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0341-1

Security update for bind

больше 3 лет назад
ubuntu логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
17%
Средний
больше 3 лет назад
redhat логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
17%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
17%
Средний
больше 3 лет назад
msrc логотип
CVE-2022-3924

named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota

CVSS3: 7.5
17%
Средний
больше 3 лет назад
debian логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` ...

CVSS3: 7.5
17%
Средний
больше 3 лет назад
github логотип
GHSA-29px-hvx8-j7xf

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
17%
Средний
больше 3 лет назад
fstec логотип
BDU:2023-07833

Уязвимость сервера DNS BIND, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
17%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 5.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an a ...

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-9mq2-v988-m7mr

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2023-3002

ELSA-2023-3002: bind security and bug fix update (MODERATE)

около 3 лет назад
fstec логотип
BDU:2022-06124

Уязвимость сервера DNS BIND, связанная с неправильным управлением внутренними ресурсами, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании» (DoS)

CVSS3: 7.5
1%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:3500-1

Security update for bind

больше 3 лет назад
oracle-oval логотип
ELSA-2023-0402

ELSA-2023-0402: bind security update (MODERATE)

больше 3 лет назад

Уязвимостей на страницу