VYPR

rpm package

opensuse/bind&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/bind&distro=openSUSE%20Tumbleweed

Vulnerabilities (124)

  • CVE-2016-9778HigJan 16, 2019
    affected < 9.16.20-1.4fixed 9.16.20-1.4

    An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a confi

  • CVE-2016-9131HigJan 12, 2017
    affected < 9.16.20-1.4fixed 9.16.20-1.4

    named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.

  • CVE-2016-8864HigNov 2, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and re

  • CVE-2016-2776HigSep 28, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

  • CVE-2016-2775MedJul 19, 2016
    affected < 9.16.20-1.4fixed 9.16.20-1.4

    ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

  • CVE-2016-2088MedMar 9, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.

  • CVE-2016-1286HigMar 9, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

  • CVE-2016-1285MedMar 9, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka contr

  • CVE-2015-8705HigJan 20, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.

  • CVE-2015-8704MedJan 20, 2016
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.

  • CVE-2015-8461Dec 16, 2015
    affected < 9.16.20-1.4fixed 9.16.20-1.4

    Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.

  • CVE-2015-8000Dec 16, 2015
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.

  • CVE-2015-5986Sep 5, 2015
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.

  • CVE-2015-5722Sep 5, 2015
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

  • CVE-2015-5477Jul 29, 2015
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

  • CVE-2015-4620Jul 8, 2015
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zo

  • CVE-2015-1349Feb 19, 2015
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect

  • CVE-2014-8680Dec 11, 2014
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.

  • CVE-2014-8500Dec 11, 2014
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

  • CVE-2014-3859Jun 13, 2014
    affected < 9.10.3P4-21.1fixed 9.10.3P4-21.1

    libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.

Page 5 of 7