7.8

CVE-2016-2776

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Linux Version 5.0
Oracle ≫ Linux Version 6
Oracle ≫ Linux Version 7
Oracle ≫ Vm Server Version 3.2
Oracle ≫ Vm Server Version 3.3
Oracle ≫ Vm Server Version 3.4
Isc ≫ Bind Update p3 Version <= 9.9.9
Isc ≫ Bind Version 9.10.0
Isc ≫ Bind Version 9.10.0 Update a1
Isc ≫ Bind Version 9.10.0 Update a2
Isc ≫ Bind Version 9.10.0 Update b1
Isc ≫ Bind Version 9.10.0 Update b2
Isc ≫ Bind Version 9.10.0 Update p1
Isc ≫ Bind Version 9.10.0 Update p2
Isc ≫ Bind Version 9.10.0 Update rc1
Isc ≫ Bind Version 9.10.0 Update rc2
Isc ≫ Bind Version 9.10.1
Isc ≫ Bind Version 9.10.1 Update b1
Isc ≫ Bind Version 9.10.1 Update b2
Isc ≫ Bind Version 9.10.1 Update p1
Isc ≫ Bind Version 9.10.1 Update p2
Isc ≫ Bind Version 9.10.1 Update rc1
Isc ≫ Bind Version 9.10.1 Update rc2
Isc ≫ Bind Version 9.10.2 Update b1
Isc ≫ Bind Version 9.10.2 Update p1
Isc ≫ Bind Version 9.10.2 Update p2
Isc ≫ Bind Version 9.10.2 Update p3
Isc ≫ Bind Version 9.10.2 Update p4
Isc ≫ Bind Version 9.10.2 Update rc1
Isc ≫ Bind Version 9.10.2 Update rc2
Isc ≫ Bind Version 9.10.3
Isc ≫ Bind Version 9.10.3 Update b1
Isc ≫ Bind Version 9.10.3 Update p1
Isc ≫ Bind Version 9.10.3 Update p2
Isc ≫ Bind Version 9.10.3 Update p3
Isc ≫ Bind Version 9.10.3 Update p4
Isc ≫ Bind Version 9.10.3 Update rc1
Isc ≫ Bind Version 9.10.4 Update p2
Isc ≫ Bind Version 9.10.4 Update p3
Isc ≫ Bind Version 9.11.0 Update a1
Isc ≫ Bind Version 9.11.0 Update a2
Isc ≫ Bind Version 9.11.0 Update a3
Isc ≫ Bind Version 9.11.0 Update b1
Isc ≫ Bind Version 9.11.0 Update b2
Isc ≫ Bind Version 9.11.0 Update b3
Isc ≫ Bind Version 9.11.0 Update rc1
Hp ≫ Hp-ux Version 11.31
Oracle ≫ Solaris Version 10.0
Oracle ≫ Solaris Version 11.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.48% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
Third Party Advisory
https://kb.isc.org/article/AA-01438
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
Third Party Advisory
https://security.gentoo.org/glsa/201610-07
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107
Third Party Advisory
https://kb.isc.org/article/AA-01435
https://kb.isc.org/article/AA-01436
http://rhn.redhat.com/errata/RHSA-2016-1944.html
http://rhn.redhat.com/errata/RHSA-2016-1945.html
http://rhn.redhat.com/errata/RHSA-2016-2099.html
http://www.securityfocus.com/bid/93188
http://www.securitytracker.com/id/1036903
https://kb.isc.org/article/AA-01419/0
Vendor Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:28.bind.asc
https://security.netapp.com/advisory/ntap-20160930-0001/
https://www.exploit-db.com/exploits/40453/