Medium severity6.8NVD Advisory· Published Mar 9, 2016· Updated May 6, 2026
CVE-2016-2088
CVE-2016-2088
Description
resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.
Affected products
29cpe:2.3:a:isc:bind:9.10.0:*:*:*:*:*:*:*+ 28 more
- cpe:2.3:a:isc:bind:9.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:a1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:a2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:b1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:b2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:p1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:p2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:b1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:b2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:p1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:p2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:b1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:p1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:p2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:p3:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:p4:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.2:rc2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.3:*:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.3:b1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.3:p1:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.3:p2:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.3:p3:*:*:*:*:*:*
- cpe:2.3:a:isc:bind:9.10.3:rc1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- kb.isc.org/article/AA-01351nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2016-April/181036.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-March/178831.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-March/179904.htmlnvd
- www.securityfocus.com/bid/84290nvd
- www.securitytracker.com/id/1035238nvd
- kb.isc.org/article/AA-01380nvd
- security.gentoo.org/glsa/201610-07nvd
News mentions
0No linked articles in our index yet.