buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Jan 20, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Mar 1, 2016 | Jan 20, 2016 |
| Freebsd | — | Upgrade bind910 | Dec 10, 2025 | Jan 20, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 20, 2016 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.6.3.11.8-0.175.3.14.0.2.0 on Solaris 11.3Upgrade service/network/dns/bind to version 9.6.3.11.8-0.175.3.14.0.2.0 on Solaris 11.3 | May 29, 2017 | Jan 20, 2016 |
| Suse | — | Upgrade python3-bindUpgrade libns1604Upgrade bind-chrootenvUpgrade bind-develUpgrade libisc1606Upgrade libirs1601Upgrade libisccfg1600Upgrade libdns1605Upgrade liblwres160Upgrade libisccc160Upgrade libisccfg160Upgrade bind-utilsUpgrade bind-docUpgrade bindUpgrade libirs-develUpgrade libisccc1600Upgrade libisc166Upgrade libbind9-1600Upgrade libdns169Upgrade libirs160Upgrade libbind9-160 | May 20, 2018 | Jan 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub