7.5

CVE-2019-6477

With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IscBind Version >= 9.11.7 <= 9.11.12
IscBind Version >= 9.14.1 <= 9.14.7
IscBind Version >= 9.15.0 <= 9.15.5
IscBind Version9.11.5 Updates6 SwEditionsupported_preview
IscBind Version9.11.6 Updatep1
IscBind Version9.11.6 Updaterc1
IscBind Version9.11.12 Updates1 SwEditionsupported_preview
IscBind Version9.12.4 Updatep1
IscBind Version9.12.4 Updatep2
FedoraprojectFedora Version30
FedoraprojectFedora Version31
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.71% 0.895
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
security-officer@isc.org 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.