← All CVEs

CVE-2016-1285

medium · 6.8

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

6.8
CVSS
59.1%
EPSS (exploit prob.)
99th
EPSS percentile
2016-03-09
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

VendorProductAffected versions
iscbind>= 9.0.0, < 9.9.8
iscbind>= 9.10.0, < 9.10.3
iscbind9.9.8
iscbind9.9.8
iscbind9.9.8
iscbind9.9.8
iscbind9.10.3
iscbind9.10.3
iscbind9.10.3
iscbind9.10.3
iscbind9.10.3
iscbind9.10.3
suselinux_enterprise_debuginfo11
suselinux_enterprise_debuginfo11
suselinux_enterprise_debuginfo11
susemanager2.1
susemanager_proxy2.1
suseopenstack_cloud5
opensuseleap42.1
opensuseopensuse11.4
opensuseopensuse13.1
opensuseopensuse13.2
suselinux_enterprise_desktop11
suselinux_enterprise_desktop12
suselinux_enterprise_desktop12
suselinux_enterprise_server11
suselinux_enterprise_server11
suselinux_enterprise_server11
suselinux_enterprise_server12
suselinux_enterprise_server12
suselinux_enterprise_software_development_kit11
suselinux_enterprise_software_development_kit12
suselinux_enterprise_software_development_kit12
fedoraprojectfedora22
fedoraprojectfedora23
fedoraprojectfedora24
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
debiandebian_linux7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-1285