PT-2023-6837 · Isc+9 · Bind 9+9

Published

2023-01-25

·

Updated

2024-06-15

·

CVE-2022-3736

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.16.12 through 9.16.36 BIND 9 versions 9.18.0 through 9.18.10 BIND 9 versions 9.19.0 through 9.19.8 BIND 9 versions 9.16.12-S1 through 9.16.36-S1
Description The issue is related to a flaw in the implementation of the stale-answer-client-timeout option, which can cause the BIND 9 resolver to crash when stale cache and stale answers are enabled and the resolver receives an RRSIG query. This can be exploited by a remote attacker to cause a denial of service. The issue is caused by insufficient input validation.
Recommendations For BIND 9 versions 9.16.12 through 9.16.36, update to a version outside of this range or apply a configuration change to disable the stale-answer-client-timeout option. For BIND 9 versions 9.18.0 through 9.18.10, update to a version outside of this range or apply a configuration change to disable the stale-answer-client-timeout option. For BIND 9 versions 9.19.0 through 9.19.8, update to a version outside of this range or apply a configuration change to disable the stale-answer-client-timeout option. For BIND 9 versions 9.16.12-S1 through 9.16.36-S1, update to a version outside of this range or apply a configuration change to disable the stale-answer-client-timeout option. As a temporary workaround, consider disabling the stale-answer-client-timeout option until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2261
ALSA-2023:2792
ALT-PU-2023-1130
ALT-PU-2023-1185
AZL-13203
BDU:2023-07832
CESA-2023_2792
CVE-2022-3736
DSA-5329-1
OESA-2023-1067
OESA-2023-1068
OPENSUSE-SU-2023_0341-1
OPENSUSE-SU-2024:12641-1
RHSA-2023:2261
RHSA-2023:2792
RHSA-2023_2261
RHSA-2023_2792
SUSE-SU-2023:0341-1
USN-5827-1

Affected Products

Alt Linux
Almalinux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Suse
Ubuntu