Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ezequiel Tavella

Pesquisador deInfobyte Research Team
#32889de 53,635
7.8CVSS total
Vulnerabilidades · 1
PT-2016-5213
7.8
2015-07-28
Isc · Isc Bind 9 · CVE-2016-2776
**Name of the Vulnerable Software and Affected Versions** ISC BIND 9 versions 9.9.9 before 9.9.9-P3 ISC BIND 9 versions 9.10.x before 9.10.4-P3 ISC BIND 9 versions 9.11.x before 9.11.0rc3 **Description** The issue allows remote attackers to cause a denial of service, resulting in an assertion failure and daemon exit, by sending a crafted query. This can also be triggered by sending an overly long request when lwresd or the named lwres option is enabled, causing the daemon to crash. **Recommendations** For ISC BIND 9 versions 9.9.9 before 9.9.9-P3, update to version 9.9.9-P3 or later. For ISC BIND 9 versions 9.10.x before 9.10.4-P3, update to version 9.10.4-P3 or later. For ISC BIND 9 versions 9.11.x before 9.11.0rc3, update to version 9.11.0rc3 or later. As a temporary workaround, consider disabling the lwresd option or the named lwres option to minimize the risk of exploitation.