PT-2022-4939 · Isc+10 · Bind+10

Maksym Odinintsev

·

Published

2022-09-14

·

Updated

2024-07-03

·

CVE-2022-3080

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions (affected versions not specified)
Description The issue is related to a flaw in the resolver code, allowing an attacker to cause the named service to crash by sending specific queries. This can lead to a denial of service (DoS) attack, where the attacker can severely degrade the resolver's performance, denying legitimate clients access to the DNS resolution service. The vulnerability is also associated with insufficient input validation when handling the stale-answer-client-timeout parameter with a value of 0 and the use of CNAME record types in the cache for incoming requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Special Elements Injection

Insufficient Session Expiration

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6763
ALSA-2022:6781
AZL-11000
BDU:2022-06125
CESA-2022_6781
CVE-2022-3080
DSA-5235-1
OESA-2022-1983
OPENSUSE-SU-2022_3767-1
OPENSUSE-SU-2024:12356-1
RHSA-2022:6763
RHSA-2022:6781
RHSA-2022_6763
RHSA-2022_6781
RLSA-2022:6763
RLSA-2022:6781
SUSE-SU-2022:3767-1
USN-5626-1

Affected Products

Almalinux
Bind
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu