Логотип exploitDog
bind:"CVE-2022-3924" OR bind:"CVE-2022-2795" OR bind:"CVE-2022-3094" OR bind:"CVE-2022-3736"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-3924" OR bind:"CVE-2022-2795" OR bind:"CVE-2022-3094" OR bind:"CVE-2022-3736"

Количество 38

Количество 38

oracle-oval логотип

ELSA-2023-2792

около 2 лет назад

ELSA-2023-2792: bind9.16 security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2261

около 2 лет назад

ELSA-2023-2261: bind security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0341-1

больше 2 лет назад

Security update for bind

EPSS: Низкий
ubuntu логотип

CVE-2022-3924

больше 2 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3924

больше 2 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-3924

больше 2 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-3924

больше 2 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29px-hvx8-j7xf

больше 2 лет назад

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-07833

больше 2 лет назад

Уязвимость сервера DNS BIND, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2795

больше 2 лет назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-2795

больше 2 лет назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-2795

больше 2 лет назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2022-2795

больше 2 лет назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-2795

больше 2 лет назад

By flooding the target resolver with queries exploiting this flaw an a ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9mq2-v988-m7mr

больше 2 лет назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-3002

около 2 лет назад

ELSA-2023-3002: bind security and bug fix update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2022-06124

почти 3 года назад

Уязвимость сервера DNS BIND, связанная с неправильным управлением внутренними ресурсами, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании» (DoS)

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3500-1

больше 2 лет назад

Security update for bind

EPSS: Низкий
oracle-oval логотип

ELSA-2023-0402

больше 2 лет назад

ELSA-2023-0402: bind security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2022-3736

больше 2 лет назад

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2023-2792

ELSA-2023-2792: bind9.16 security and bug fix update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-2261

ELSA-2023-2261: bind security and bug fix update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0341-1

Security update for bind

больше 2 лет назад
ubuntu логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-3924

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` ...

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-29px-hvx8-j7xf

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-07833

Уязвимость сервера DNS BIND, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 5.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an a ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-9mq2-v988-m7mr

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-3002

ELSA-2023-3002: bind security and bug fix update (MODERATE)

около 2 лет назад
fstec логотип
BDU:2022-06124

Уязвимость сервера DNS BIND, связанная с неправильным управлением внутренними ресурсами, позволяющая нарушителю выполнить атаку типа «отказ в обслуживании» (DoS)

CVSS3: 7.5
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3500-1

Security update for bind

больше 2 лет назад
oracle-oval логотип
ELSA-2023-0402

ELSA-2023-0402: bind security update (MODERATE)

больше 2 лет назад
ubuntu логотип
CVE-2022-3736

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу