The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 8, 2015 | Dec 10, 2014 |
| Freebsd | — | Upgrade bind98-baseUpgrade bind96Upgrade bind99-baseUpgrade FreeBSDUpgrade bind99Upgrade bind96-baseUpgrade bind98 | Dec 10, 2025 | Dec 11, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Dec 10, 2014 |
| Suse | — | Upgrade libns1604Upgrade libisc1606Upgrade bind-develUpgrade liblwres160Upgrade libirs1601Upgrade libisccfg160Upgrade libbind9-160Upgrade libdns1605Upgrade libisccc160Upgrade python3-bindUpgrade libisccc1600Upgrade libisccfg1600Upgrade bind-utilsUpgrade libdns169Upgrade libisc166Upgrade bind-docUpgrade bind-chrootenvUpgrade bindUpgrade libirs-develUpgrade libirs160Upgrade libbind9-1600 | May 20, 2018 | Dec 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub