Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-4236
HistorySep 20, 2023 - 1:15 p.m.

CVE-2023-4236

2023-09-2013:15:12
Alpine Linux Development Team
security.alpinelinux.org
15
flaw in networking
dns-over-tls
'named' termination
assertion failure
bind 9
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

35.0%

A flaw in the networking code handling DNS-over-TLS queries may cause named to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load.
This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.

OSVersionArchitecturePackageVersionFilename
Alpineedge-mainnoarchbind< 9.18.19-r0UNKNOWN
Alpine3.17-mainnoarchbind< 9.18.19-r0UNKNOWN
Alpine3.18-mainnoarchbind< 9.18.19-r0UNKNOWN
Alpine3.19-mainnoarchbind< 9.18.19-r0UNKNOWN
Alpine3.20-mainnoarchbind< 9.18.19-r0UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

35.0%