Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41083
HistoryJun 30, 2023 - 3:31 a.m.

Denial Of Service (DoS)

2023-06-3003:31:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
denial of service
libbind9.so
bind 9 resolver
vulnerability
stack overflow
application crash

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

49.4%

libbind9.so is vulnerable to Denial Of Service. The vulnerability exists if the recursive-clients quota is reached on a BIND 9 resolver configured with both stale-answer-enable yes and stale-answer-client-timeout 0, which leads to a sequence of serve-stale-related lookups could cause the named to loop and terminate unexpectedly due to a stack overflow, allowing an attacker to cause an application crash.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

49.4%