QID 15147
Date Published: 2023-07-25
QID 15147: ISC BIND Denial of Service (DoS) Vulnerability (CVE-2015-8000)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
An error in the parsing of incoming responses allows some records with an incorrect class to be accepted by BIND 9, instead of being rejected as malformed.
BIND Affected versions:
9.0.x - 9.9.8
9.10.0 - 9.10.3
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successful exploitation of this vulnerability may allow an attacker to cause a server to request a record with a malformed class attribute can use this bug to trigger a REQUIRE assertion in db.c, causing named to exit and denying service to clients.
Solution
Customers are advised to upgrade latest release of ISC BIND.
Vendor References
- CVE-2015-8000 -
kb.isc.org/docs/aa-01317
CVEs related to QID 15147
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2015-8000 |
|