ZeroHour

CVE-2016-1285

CVSS 3.1
6.8 medium
EPSS
59%p99
Published
()
Modified
Description

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

Vendors
iscsuseopensusefedoraprojectcanonicaldebianjuniper
Products
bind, linux enterprise debuginfo, manager, manager proxy, openstack cloud, leap, opensuse, linux enterprise desktop, linux enterprise server, linux enterprise software development kit, fedora, ubuntu linux
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.