Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2016-1285

Published: March 9, 2016Last modified: December 1, 2023

Description

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

Severity score breakdown

ParameterValue
Base score6.8
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbindNot affected (9.18.16-r0)
StreambindNot affected (9.18.18-r0)

References

ON THIS PAGE