← All CVEs

CVE-2015-4620

high · 7.8

name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.

7.8
CVSS
37.9%
EPSS (exploit prob.)
98th
EPSS percentile
2015-07-08
Published

AV:N/AC:L/Au:N/C:N/I:N/A:C

Weaknesses

CWE-17

Affected products

VendorProductAffected versions
iscbind9.7.0
iscbind9.7.0
iscbind9.7.0
iscbind9.7.0
iscbind9.7.0
iscbind9.7.0
iscbind9.7.1
iscbind9.7.1
iscbind9.7.1
iscbind9.7.1
iscbind9.7.2
iscbind9.7.2
iscbind9.7.2
iscbind9.7.2
iscbind9.7.2
iscbind9.7.3
iscbind9.7.3
iscbind9.7.3
iscbind9.7.3
iscbind9.7.4
iscbind9.7.4
iscbind9.7.4
iscbind9.7.4
iscbind9.7.5
iscbind9.7.5
iscbind9.7.5
iscbind9.7.5
iscbind9.7.6
iscbind9.7.6
iscbind9.7.6
iscbind9.7.7
iscbind9.8.0
iscbind9.8.0
iscbind9.8.0
iscbind9.8.0
iscbind9.8.0
iscbind9.8.0
iscbind9.8.0
iscbind9.8.1
iscbind9.8.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-4620