4.3

CVE-2012-3868

Race condition in the ns_client structure management in ISC BIND 9.9.x before 9.9.1-P2 allows remote attackers to cause a denial of service (memory consumption or process exit) via a large volume of TCP queries.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind Version 9.9.0
Isc ≫ Bind Version 9.9.0 Update a1
Isc ≫ Bind Version 9.9.0 Update a2
Isc ≫ Bind Version 9.9.0 Update a3
Isc ≫ Bind Version 9.9.0 Update b1
Isc ≫ Bind Version 9.9.0 Update b2
Isc ≫ Bind Version 9.9.0 Update rc1
Isc ≫ Bind Version 9.9.0 Update rc2
Isc ≫ Bind Version 9.9.0 Update rc3
Isc ≫ Bind Version 9.9.0 Update rc4
Isc ≫ Bind Version 9.9.1
Isc ≫ Bind Version 9.9.1 Update p1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.72% 0.841
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004
https://kb.isc.org/article/AA-00730
Vendor Advisory