Lucene search

K
debianDebianDEBIAN:DLA-285-1:3629A
HistoryJul 28, 2015 - 7:23 p.m.

[SECURITY] [DLA 285-1] bind9 security update

2015-07-2819:23:41
lists.debian.org
11

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

7.5

Confidence

High

EPSS

0.972

Percentile

99.8%

Package : bind9
Version : 1:9.7.3.dfsg-1~squeeze16
CVE ID : CVE-2015-5477

Jonathan Foote discovered that the BIND DNS server does not properly
handle TKEY queries. A remote attacker can take advantage of this flaw
to mount a denial of service via a specially crafted query triggering an
assertion failure and causing BIND to exit.

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

7.5

Confidence

High

EPSS

0.972

Percentile

99.8%