QID 15146
Date Published: 2023-07-25
QID 15146: ISC BIND Denial of Service (DoS) Vulnerability (CVE-2015-8461)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
An uncommonly occurring condition can cause affected servers to exit with an INSIST failure depending on the outcome of a race condition in resolver.c.
BIND Affected versions:
9.9.8 -> 9.9.8-P1
9.9.8-S1 -> 9.9.8-S2
9.10.3 -> 9.10.3-P1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successful exploitation of this vulnerability may allow an attacker through deliberate behavior, significantly increase the probability of encountering the triggering condition, resulting in denial of service.
Solution
Customers are advised to upgrade latest release of ISC BIND.
Vendor References
- CVE-2015-8461 -
kb.isc.org/docs/aa-01319
CVEs related to QID 15146
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2015-8461 |
|