7.5
CVE-2016-8864
- EPSS 38.73%
- Veröffentlicht 02.11.2016 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Data Ontap Edge Version -
Netapp ≫ Steelstore Cloud Integrated Storage Version -
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 6.2
Redhat ≫ Enterprise Linux Server Aus Version 6.4
Redhat ≫ Enterprise Linux Server Aus Version 6.5
Redhat ≫ Enterprise Linux Server Aus Version 6.6
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Tus Version 6.5
Redhat ≫ Enterprise Linux Server Tus Version 6.6
Redhat ≫ Enterprise Linux Server Tus Version 7.2
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Debian ≫ Debian Linux Version 8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 38.73% | 0.984 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://kb.isc.org/article/AA-01438
https://kb.isc.org/article/AA-01435
https://kb.isc.org/article/AA-01436
https://security.netapp.com/advisory/ntap-20180926-0005/
http://rhn.redhat.com/errata/RHSA-2016-2141.html
http://rhn.redhat.com/errata/RHSA-2016-2142.html
http://rhn.redhat.com/errata/RHSA-2016-2615.html
http://rhn.redhat.com/errata/RHSA-2016-2871.html
http://www.debian.org/security/2016/dsa-3703
http://www.securityfocus.com/bid/94067
http://www.securitytracker.com/id/1037156
https://access.redhat.com/errata/RHSA-2017:1583
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05381687
https://kb.isc.org/article/AA-01434
https://kb.isc.org/article/AA-01437
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:34.bind.asc
https://security.gentoo.org/glsa/201701-26