Lucene search

K
freebsdFreeBSDC93533A3-24F1-11E5-8B74-3C970E169BC2
HistoryJul 07, 2015 - 12:00 a.m.

bind -- denial of service vulnerability

2015-07-0700:00:00
vuxml.freebsd.org
22

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.157

Percentile

96.0%

ISC reports:

A very uncommon combination of zone data has been found
that triggers a bug in BIND, with the result that named
will exit with a “REQUIRE” failure in name.c when validating
the data returned in answer to a recursive query.
A recursive resolver that is performing DNSSEC validation
can be deliberately terminated by any attacker who can
cause a query to be performed against a maliciously
constructed zone. This will result in a denial of
service to clients who rely on that resolver.

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.157

Percentile

96.0%