7.8

CVE-2015-5477

Warnung
Medienbericht
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind Update p1 Version <= 9.9.7
Isc ≫ Bind Update p2 Version <= 9.10.2

08.10.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

ISC BIND Data Processing Errors Vulnerability

Schwachstelle

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.28% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.10.2026 23:59
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.10.2026 20:58
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
http://marc.info/?l=bugtraq&m=144000632319155&w=2
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
https://security.gentoo.org/glsa/201510-01
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html
http://marc.info/?l=bugtraq&m=144017354030745&w=2
http://marc.info/?l=bugtraq&m=144181171013996&w=2
http://marc.info/?l=bugtraq&m=144294073801304&w=2
http://www.debian.org/security/2015/dsa-3319
http://www.securityfocus.com/bid/76092
http://www.securitytracker.com/id/1033100
https://security.netapp.com/advisory/ntap-20160114-0001/
https://www.exploit-db.com/exploits/37721/
https://www.exploit-db.com/exploits/37723/
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html
http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html
http://rhn.redhat.com/errata/RHSA-2015-1513.html
http://rhn.redhat.com/errata/RHSA-2015-1514.html
http://rhn.redhat.com/errata/RHSA-2015-1515.html
http://rhn.redhat.com/errata/RHSA-2016-0078.html
http://rhn.redhat.com/errata/RHSA-2016-0079.html
http://www.ubuntu.com/usn/USN-2693-1
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918
https://kb.isc.org/article/AA-01272
Patch
Vendor Advisory
https://kb.isc.org/article/AA-01305
https://kb.isc.org/article/AA-01306
https://kb.isc.org/article/AA-01307
https://kb.isc.org/article/AA-01438
https://kb.juniper.net/JSA10783
https://kc.mcafee.com/corporate/index?page=content&id=SB10126
https://support.apple.com/kb/HT205032
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5477