VYPR

Bind

by Isc

Source repositories

CVEs (225)

  • CVE-2022-2906HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.02

    An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

  • CVE-2022-1183HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.06

    On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and…

  • CVE-2022-0635HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.

  • CVE-2022-0667HigMar 22, 2022
    risk 0.49cvss 7.5epss 0.01

    When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

  • CVE-2021-25218HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.04

    In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vulnerability affects only BIND…

  • CVE-2020-8623HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.06

    In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system…

  • CVE-2020-8621HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.03

    In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not…

  • CVE-2020-8620HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.04

    In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.

  • CVE-2019-6477HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.04

    With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been…

  • CVE-2018-5742HigOct 30, 2019
    risk 0.49cvss 7.5epss 0.02

    While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the…

  • CVE-2019-6469HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.02

    An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview Edition.

  • CVE-2019-6468HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.03

    In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. In those versions which have ECS support, enabling nxdomain-redirect is likely to lead to BIND exiting due to assertion failure.…

  • CVE-2019-6467HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.05

    A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to…

  • CVE-2018-5744HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.03

    A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions…

  • CVE-2018-5743HigOct 9, 2019
    risk 0.49cvss 7.5epss 0.06

    By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to…

  • CVE-2017-3139HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.02

    A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.

  • CVE-2018-5734HigJan 16, 2019
    risk 0.49cvss 7.5epss 0.06

    While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of…

  • CVE-2017-3137HigJan 16, 2019
    risk 0.49cvss 7.5epss 0.09

    Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual…

  • CVE-2016-9778HigJan 16, 2019
    risk 0.49cvss 7.5epss 0.07

    An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a…

  • CVE-2016-1285MedMar 9, 2016
    risk 0.49cvss 6.8epss 0.59

    named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka…

Page 4 of 12