resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Mar 9, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Aug 2, 2016 | Mar 9, 2016 |
| Freebsd | — | Upgrade bind910Upgrade bind9-devel | Dec 10, 2025 | Mar 28, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Mar 9, 2016 |
| Suse | — | Upgrade bindUpgrade liblwres160Upgrade libdns169Upgrade libisc1606Upgrade libirs-develUpgrade libisccfg160Upgrade bind-docUpgrade libbind9-1600Upgrade libirs1601Upgrade bind-develUpgrade libdns1605Upgrade libisc166Upgrade libbind9-160Upgrade bind-chrootenvUpgrade libirs160Upgrade libisccfg1600Upgrade libisccc1600Upgrade python3-bindUpgrade libns1604Upgrade bind-utilsUpgrade libisccc160 | May 20, 2018 | Mar 9, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub