7.5

CVE-2016-8864

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IscBind Version >= 9.0.0 < 9.9.9
IscBind Version >= 9.10.0 < 9.10.4
IscBind Version9.9.9 Update-
IscBind Version9.9.9 Updatebeta1
IscBind Version9.9.9 Updatebeta2
IscBind Version9.9.9 Updatep1
IscBind Version9.9.9 Updatep2
IscBind Version9.9.9 Updatep3
IscBind Version9.10.4 Update-
IscBind Version9.10.4 Updatebeta1
IscBind Version9.10.4 Updatebeta2
IscBind Version9.10.4 Updatebeta3
IscBind Version9.10.4 Updatep1
IscBind Version9.10.4 Updatep2
IscBind Version9.10.4 Updatep3
IscBind Version9.11.0 Update-
IscBind Version9.11.0 Updatealpha1
IscBind Version9.11.0 Updatealpha2
IscBind Version9.11.0 Updatealpha3
IscBind Version9.11.0 Updatebeta1
IscBind Version9.11.0 Updatebeta2
IscBind Version9.11.0 Updatebeta3
NetappData Ontap Edge Version-
NetappSolidfire Version-
RedhatEnterprise Linux Eus Version6.7
RedhatEnterprise Linux Eus Version7.2
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 43.01% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.