QID 15145
Date Published: 2023-07-25
QID 15145: ISC BIND Denial of Service (DoS) Vulnerability (CVE-2016-2848)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
A packet with a malformed options section can be used to deliberately trigger an assertion failure.
BIND Affected versions:
9.1.0 - 9.8.4-P2
9.9.0 -> 9.9.2-P2
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successful exploitation of this vulnerability may allow an attacker to force exit with an assertion failure if it receives a malformed packet causing Denial Of Service.
Solution
Customers are advised to upgrade latest release of ISC BIND.
Vendor References
- CVE-2016-2848 -
kb.isc.org/docs/aa-01433
CVEs related to QID 15145
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2016-2848 |
|