4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:N/I:N/A:P
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
0.01 Low
EPSS
Percentile
83.9%
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through
9.11.0b1 allows primary DNS servers to cause a denial of service (secondary
DNS server crash) via a large AXFR response, and possibly allows IXFR
servers to cause a denial of service (IXFR client crash) via a large IXFR
response and allows remote authenticated users to cause a denial of service
(primary DNS server crash) via a large UPDATE message.
www.openwall.com/lists/oss-security/2016/07/06/3
github.com/sischkg/xfer-limit/blob/master/README.md
gitlab.isc.org/isc-projects/bind9/-/commit/5f8412a4cb5ee14a0e8cddd4107854b40ee3291e
kb.isc.org/article/AA-01390/0/Operational-Notification%3A-A-party-that-is-allowed-control-over-zone-data-can-overwhelm-a-server-by-transferring-huge-quantities-of-data.html
launchpad.net/bugs/cve/CVE-2016-6170
lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html
lists.dns-oarc.net/pipermail/dns-operations/2016-July/015073.html
lists.dns-oarc.net/pipermail/dns-operations/2016-July/015075.html
nvd.nist.gov/vuln/detail/CVE-2016-6170
security-tracker.debian.org/tracker/CVE-2016-6170
ubuntu.com/security/notices/USN-5747-1
www.cve.org/CVERecord?id=CVE-2016-6170
4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:N/I:N/A:P
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
0.01 Low
EPSS
Percentile
83.9%