Lucene search

K
f5F5F5:K16909
HistoryNov 03, 2015 - 12:00 a.m.

K16909 : BIND vulnerability CVE-2015-5477

2015-11-0300:00:00
my.f5.com
34

8.1 High

AI Score

Confidence

High

0.972 High

EPSS

Percentile

99.8%

Security Advisory Description

An error in the handling of TKEY queries can be exploited by an attacker for use as a denial-of-service vector, as a constructed packet can use the defect to trigger a REQUIRE assertion failure, causing BIND to exit. (CVE-2015-5477)
Impact
A remote attacker may be able to cause a denial-of-service (DoS) attack on the BIG-IP system’s local instance of BIND by using a specially crafted DNS request in configurations that expose BIND to requests from untrusted users.
Note: If theBIND daemon stops responding, services that do not rely on the use of local instances of BIND will continue to function.