CVE Vulnerabilities

CVE-2016-1285

Published: Mar 09, 2016 | Modified: Nov 30, 2023
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

Affected Software

Name Vendor Start Version End Version
Bind Isc 9.0.0 (including) 9.9.8 (excluding)
Bind Isc 9.10.0 (including) 9.10.3 (excluding)
Bind Isc 9.9.8 (including) 9.9.8 (including)
Bind Isc 9.9.8-p2 (including) 9.9.8-p2 (including)
Bind Isc 9.9.8-p3 (including) 9.9.8-p3 (including)
Bind Isc 9.9.8-rc1 (including) 9.9.8-rc1 (including)
Bind Isc 9.10.3 (including) 9.10.3 (including)
Bind Isc 9.10.3-beta1 (including) 9.10.3-beta1 (including)
Bind Isc 9.10.3-p1 (including) 9.10.3-p1 (including)
Bind Isc 9.10.3-p2 (including) 9.10.3-p2 (including)
Bind Isc 9.10.3-p3 (including) 9.10.3-p3 (including)
Bind Isc 9.10.3-rc1 (including) 9.10.3-rc1 (including)

References