CVE-2016-1285

MEDIUM

ISC BIND 9.x <9.9.8-P4,9.10.x <9.10.3-P4 - DoS

Title source: llm

Description

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

References (29)

... and 9 more

Scores

CVSS v3 6.8
EPSS 0.5500
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Classification

Status draft

Affected Products (50)

isc/bind < 9.9.8
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
suse/linux_enterprise_debuginfo
suse/linux_enterprise_debuginfo
suse/linux_enterprise_debuginfo
suse/manager
... and 35 more

Timeline

Published Mar 09, 2016
Tracked Since Feb 18, 2026