6.8

CVE-2016-2088

resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind Version 9.10.0
Isc ≫ Bind Version 9.10.0 Update a1
Isc ≫ Bind Version 9.10.0 Update a2
Isc ≫ Bind Version 9.10.0 Update b1
Isc ≫ Bind Version 9.10.0 Update b2
Isc ≫ Bind Version 9.10.0 Update p1
Isc ≫ Bind Version 9.10.0 Update p2
Isc ≫ Bind Version 9.10.0 Update rc1
Isc ≫ Bind Version 9.10.0 Update rc2
Isc ≫ Bind Version 9.10.1
Isc ≫ Bind Version 9.10.1 Update b1
Isc ≫ Bind Version 9.10.1 Update b2
Isc ≫ Bind Version 9.10.1 Update p1
Isc ≫ Bind Version 9.10.1 Update p2
Isc ≫ Bind Version 9.10.1 Update rc1
Isc ≫ Bind Version 9.10.1 Update rc2
Isc ≫ Bind Version 9.10.2 Update b1
Isc ≫ Bind Version 9.10.2 Update p1
Isc ≫ Bind Version 9.10.2 Update p2
Isc ≫ Bind Version 9.10.2 Update p3
Isc ≫ Bind Version 9.10.2 Update p4
Isc ≫ Bind Version 9.10.2 Update rc1
Isc ≫ Bind Version 9.10.2 Update rc2
Isc ≫ Bind Version 9.10.3
Isc ≫ Bind Version 9.10.3 Update b1
Isc ≫ Bind Version 9.10.3 Update p1
Isc ≫ Bind Version 9.10.3 Update p2
Isc ≫ Bind Version 9.10.3 Update p3
Isc ≫ Bind Version 9.10.3 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.79% 0.975
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 2.2 4
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://kb.isc.org/article/AA-01380
https://security.gentoo.org/glsa/201610-07
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181036.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178831.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179904.html
http://www.securityfocus.com/bid/84290
http://www.securitytracker.com/id/1035238
https://kb.isc.org/article/AA-01351
Vendor Advisory