PT-2016-5237 · Isc+4 · Isc Bind+4

Dhiru Kholia

·

Publicado

2016-10-20

·

Atualizado

2018-09-27

·

CVE-2016-2848

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ISC BIND versions 9.1.0 through 9.8.4-P2 ISC BIND versions 9.9.0 through 9.9.2-P2
Description The issue allows remote attackers to cause a denial of service, resulting in an assertion failure and daemon exit, by sending a specially crafted DNS packet with malformed options data in an OPT resource record.
Recommendations For versions 9.1.0 through 9.8.4-P2, update to a version later than 9.8.4-P2 to resolve the issue. For versions 9.9.0 through 9.9.2-P2, update to a version later than 9.9.2-P2 to resolve the issue. As a temporary workaround, consider restricting access to the DNS service to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2016_2093
CVE-2016-2848
DLA-672-1
RHSA-2016:2093
RHSA-2016:2094
RHSA-2016:2099
RHSA-2016_2093
RHSA-2016_2094
USN-3108-1

Produtos afetados

Bind Server
Centos
Ibm Aix
Isc Bind
Red Hat