Lucene search

K
redosRedosROS-20220209-01
HistoryFeb 09, 2022 - 12:00 a.m.

ROS-20220209-01

2022-02-0900:00:00
redos.red-soft.ru
16
bind dns server
resource exhaustion
denial-of-service
remote attack
unix

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.007

Percentile

80.6%

A vulnerability in the BIND DNS server is related to improper consumption of internal resources during cache processing.
Exploitation of the vulnerability could allow an attacker acting remotely to cause resource exhaustion and
Perform a denial-of-service (DoS) attack

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64bind< 9.16.16-3UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.007

Percentile

80.6%