PT-2016-5237 · Isc+4 · Isc Bind+4

Dhiru Kholia

·

Published

2016-10-20

·

Updated

2018-09-27

·

CVE-2016-2848

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ISC BIND versions 9.1.0 through 9.8.4-P2 ISC BIND versions 9.9.0 through 9.9.2-P2
Description The issue allows remote attackers to cause a denial of service, resulting in an assertion failure and daemon exit, by sending a specially crafted DNS packet with malformed options data in an OPT resource record.
Recommendations For versions 9.1.0 through 9.8.4-P2, update to a version later than 9.8.4-P2 to resolve the issue. For versions 9.9.0 through 9.9.2-P2, update to a version later than 9.9.2-P2 to resolve the issue. As a temporary workaround, consider restricting access to the DNS service to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2016_2093
CVE-2016-2848
DLA-672-1
RHSA-2016:2093
RHSA-2016:2094
RHSA-2016:2099
RHSA-2016_2093
RHSA-2016_2094
USN-3108-1

Affected Products

Bind Server
Centos
Ibm Aix
Isc Bind
Red Hat