5.9

CVE-2016-2775

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Hp-ux Version b.11.31
Isc ≫ Bind Version >= 9.0 <= 9.9.8
Isc ≫ Bind Version >= 9.10.0 <= 9.10.3
Isc ≫ Bind Version 9.9.9 Update -
Isc ≫ Bind Version 9.9.9 Update b1
Isc ≫ Bind Version 9.9.9 Update b2
Isc ≫ Bind Version 9.9.9 Update p1
Isc ≫ Bind Version 9.9.9 Update rc1
Isc ≫ Bind Version 9.9.9 Update s1
Isc ≫ Bind Version 9.9.9 Update s1rc1
Isc ≫ Bind Version 9.10.4 Update -
Isc ≫ Bind Version 9.10.4 Update beta1
Isc ≫ Bind Version 9.10.4 Update beta2
Isc ≫ Bind Version 9.10.4 Update beta3
Isc ≫ Bind Version 9.10.4 Update p1
Isc ≫ Bind Version 9.11.0 Update -
Isc ≫ Bind Version 9.11.0 Update alpha1
Isc ≫ Bind Version 9.11.0 Update alpha2
Isc ≫ Bind Version 9.11.0 Update alpha3
Isc ≫ Bind Version 9.11.0 Update beta1
Fedoraproject ≫ Fedora Version 23
Fedoraproject ≫ Fedora Version 24
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 63.35% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://kb.isc.org/article/AA-01438
Broken Link
https://security.gentoo.org/glsa/201610-07
Third Party Advisory
http://www.securityfocus.com/bid/92037
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036360
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHBA-2017:0651
Third Party Advisory
https://access.redhat.com/errata/RHBA-2017:1767
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2533
Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107
Patch
Vendor Advisory
https://kb.isc.org/article/AA-01393/74/CVE-2016-2775
Patch
Vendor Advisory
https://kb.isc.org/article/AA-01435
Broken Link
https://kb.isc.org/article/AA-01436
Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7T2WJP5ELO4ZRSBXSETIZ3GAO6KOEFTA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZUCSMEOZIZ2R2SKA4FPLTOVZHJBAOWC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ5STNEUHBNEPUHJT7CYEVSMATFYMIX7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT754KDUJTKOASJODJX7FKHCOQ6EC7UX/
https://security.netapp.com/advisory/ntap-20160722-0002/
Third Party Advisory