Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Dec 16, 2015 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jan 7, 2016 | Dec 16, 2015 |
| Freebsd | — | Upgrade bind9-develUpgrade bind99Upgrade FreeBSDUpgrade bind910 | Dec 10, 2025 | Dec 16, 2015 |
| Suse | — | Upgrade libbind9-1600Upgrade libdns1605Upgrade libisccfg160Upgrade libirs1601Upgrade libns1604Upgrade libisccc160Upgrade bind-utilsUpgrade liblwres160Upgrade libisccfg1600Upgrade python3-bindUpgrade libisc1606Upgrade libisccc1600Upgrade bind-chrootenvUpgrade libisc166Upgrade libirs-develUpgrade bindUpgrade bind-develUpgrade libirs160Upgrade libbind9-160Upgrade bind-docUpgrade libdns169 | May 20, 2018 | Dec 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub