7.5

CVE-2022-3736

named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query.
This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind SwEdition - Version >= 9.16.12 < 9.16.37
Isc ≫ Bind SwEdition - Version >= 9.18.0 < 9.18.11
Isc ≫ Bind SwEdition - Version >= 9.19.0 < 9.19.9
Isc ≫ Bind Version 9.16.11 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.13 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.14 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.21 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.32 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.36 Update s1 SwEdition supported_preview
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 48.71% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ISC 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.