PT-2016-1132 · Isc+8 · Isc Bind 9.X+8

Publicado

2016-01-19

·

Atualizado

2024-06-15

·

CVE-2015-8704

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC BIND 9.x versions 9.9.8-P3 and earlier, 9.9.x, and 9.10.x versions prior to 9.10.3-P3
Description The issue is caused by insufficient input validation, allowing a remote authenticated attacker to cause a denial of service via a malformed Address Prefix List (APL) record. This can lead to an INSIST assertion failure and daemon exit. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the use of a specially crafted Address Prefix List (APL) record to trigger the INSIST assertion failure.
Recommendations For ISC BIND 9.x versions prior to 9.9.8-P3, update to version 9.9.8-P3 or later. For ISC BIND 9.9.x, update to a version that includes the fix for this issue. For ISC BIND 9.10.x versions prior to 9.10.3-P3, update to version 9.10.3-P3 or later. As a temporary workaround, consider restricting access to the apl 42.c function until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00393
CESA-2016_0073
CVE-2015-8704
DLA-396-1
DSA-3449-1
FREEBSD-SA-16_08
HPSBUX03552
MGASA-2016-0030
OPENSUSE-SU-2016_0197-1
OPENSUSE-SU-2016_0199-1
OPENSUSE-SU-2016_0204-1
OPENSUSE-SU-2024:10467-1
RHSA-2016:0073
RHSA-2016:0074
RHSA-2016_0073
RHSA-2016_0074
SUSE-SU-2016:0174-1
SUSE-SU-2016:0180-1
SUSE-SU-2016:0200-1
SUSE-SU-2016_0174-1
SUSE-SU-2016_0180-1
SUSE-SU-2016_0200-1
USN-2874-1

Produtos afetados

Bind Server
Centos
Freebsd
Hp-Ux
Ibm Aix
Isc Bind 9.X
Red Hat
Suse
Ubuntu