5.9

CVE-2016-1284

rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind Version 9.9.8 Update s1
Isc ≫ Bind Version 9.9.8 Update s2
Isc ≫ Bind Version 9.9.8 Update s3
Isc ≫ Bind Version 9.9.8 Update s4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.34% 0.874
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://kb.isc.org/article/AA-01438
Release Notes
http://www.securitytracker.com/id/1034935
https://kb.isc.org/article/AA-01348
Vendor Advisory