QID 15139
Date Published: 2023-05-29
QID 15139: ISC BIND Buffer Overflow Vulnerability (CVE-2022-2906, CVE-2022-2881)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
CVE-2021-25216: A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack.
Affected software:
BIND 9.18.0 -9.18.6
BIND 9.19.0 -9.19.4
Patched Versions:
BIND 9.18.7
BIND 9.19.5
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successfully exploitation could affects integrity, availability, confidentiality
Solution
Customers are advised to upgrade to the patched version 9.18.7, 9.19.5 or latest release of ISC BIND.Workaround:
Disable the statistics channel for CVE-2022-2881.
Disable the statistics channel for CVE-2022-2881.
Vendor References
- CVE-2022-2881 -
kb.isc.org/v1/docs/cve-2022-2881 - CVE-2022-2906 -
kb.isc.org/v1/docs/cve-2022-2906
CVEs related to QID 15139
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-2906,CVE-2022-2881, |
|