vulnerability
Amazon Linux 2023: CVE-2022-3080: Important priority package update for bind
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | 2022-09-21 | 2025-02-17 | 2025-02-17 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
2022-09-21
Added
2025-02-17
Modified
2025-02-17
Description
By sending specific queries to the resolver, an attacker can cause named to crash.
A flaw was found in the Bind package, where the resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to 0 and there is a stale CNAME in the cache for an incoming query. By sending specific queries to the resolver, an attacker can cause named to crash.
A flaw was found in the Bind package, where the resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to 0 and there is a stale CNAME in the cache for an incoming query. By sending specific queries to the resolver, an attacker can cause named to crash.
Solution(s)
amazon-linux-2023-upgrade-bindamazon-linux-2023-upgrade-bind-chrootamazon-linux-2023-upgrade-bind-debuginfoamazon-linux-2023-upgrade-bind-debugsourceamazon-linux-2023-upgrade-bind-develamazon-linux-2023-upgrade-bind-dlz-filesystemamazon-linux-2023-upgrade-bind-dlz-filesystem-debuginfoamazon-linux-2023-upgrade-bind-dlz-ldapamazon-linux-2023-upgrade-bind-dlz-ldap-debuginfoamazon-linux-2023-upgrade-bind-dlz-mysqlamazon-linux-2023-upgrade-bind-dlz-mysql-debuginfoamazon-linux-2023-upgrade-bind-dlz-sqlite3amazon-linux-2023-upgrade-bind-dlz-sqlite3-debuginfoamazon-linux-2023-upgrade-bind-dnssec-docamazon-linux-2023-upgrade-bind-dnssec-utilsamazon-linux-2023-upgrade-bind-dnssec-utils-debuginfoamazon-linux-2023-upgrade-bind-libsamazon-linux-2023-upgrade-bind-libs-debuginfoamazon-linux-2023-upgrade-bind-licenseamazon-linux-2023-upgrade-bind-pkcs11amazon-linux-2023-upgrade-bind-pkcs11-debuginfoamazon-linux-2023-upgrade-bind-pkcs11-develamazon-linux-2023-upgrade-bind-pkcs11-libsamazon-linux-2023-upgrade-bind-pkcs11-libs-debuginfoamazon-linux-2023-upgrade-bind-pkcs11-utilsamazon-linux-2023-upgrade-bind-pkcs11-utils-debuginfoamazon-linux-2023-upgrade-bind-utilsamazon-linux-2023-upgrade-bind-utils-debuginfoamazon-linux-2023-upgrade-python3-bind

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.