The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Dns Bind | — | Upgrade ISC BIND to latest version | May 12, 2014 | May 8, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | May 8, 2014 |
| Suse | — | Upgrade libbind9-160Upgrade libdns1605Upgrade bindUpgrade libisccc160Upgrade libisccfg160Upgrade libisc166Upgrade python3-bindUpgrade libns1604Upgrade libdns169Upgrade libbind9-1600Upgrade libirs-develUpgrade libisc1606Upgrade liblwres160Upgrade bind-docUpgrade libirs160Upgrade libisccfg1600Upgrade libirs1601Upgrade bind-develUpgrade bind-chrootenvUpgrade libisccc1600Upgrade bind-utils | May 20, 2018 | May 8, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub