Lucene search

K
freebsdFreeBSD2892A8E2-3D68-11E2-8E01-0800273FE665
HistoryNov 27, 2012 - 12:00 a.m.

dns/bind9* -- servers using DNS64 can be crashed by a crafted query

2012-11-2700:00:00
vuxml.freebsd.org
13

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.035

Percentile

91.6%

ISC reports:

BIND 9 nameservers using the DNS64 IPv6 transition mechanism are
vulnerable to a software defect that allows a crafted query to
crash the server with a REQUIRE assertion failure. Remote
exploitation of this defect can be achieved without extensive
effort, resulting in a denial-of-service (DoS) vector against
affected servers.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchbind99<Β 9.9.2.1UNKNOWN
FreeBSDanynoarchbind99-base<Β 9.9.2.1UNKNOWN
FreeBSDanynoarchbind98<Β 9.8.4.1UNKNOWN
FreeBSDanynoarchbind98-base<Β 9.8.4.1UNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.035

Percentile

91.6%