ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Bind_advisory13 | — | — | Dec 19, 2016 | Jul 19, 2016 |
| Aix 6.1.9 Bind_advisory13 | — | — | Dec 19, 2016 | Jul 19, 2016 |
| Aix 7.1.3 Bind_advisory13 | — | — | Dec 19, 2016 | Jul 19, 2016 |
| Aix 7.1.4 Bind_advisory13 | — | — | Dec 19, 2016 | Jul 19, 2016 |
| Aix 7.2.0 Bind_advisory13 | — | — | Dec 19, 2016 | Jul 19, 2016 |
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Jul 19, 2016 |
| Amazon_linux | — | Upgrade bind | Sep 16, 2016 | Jul 19, 2016 |
| Centos_linux | — | Upgrade bind-pkcs11Upgrade bind-pkcs11-develUpgrade bindUpgrade bind-sdbUpgrade bind-debuginfoNo fixes or workaround suggested by the vendorUpgrade bind-pkcs11-utilsUpgrade bind-sdb-chrootUpgrade bind-licenseUpgrade bind-libsUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-pkcs11-libsUpgrade bind-lite-develUpgrade bind-develUpgrade bind-utils | Aug 28, 2019 | Jul 19, 2016 |
| Debian | — | Upgrade bind9 | Sep 28, 2016 | Jul 19, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Aug 2, 2016 | Jul 19, 2016 |
| Freebsd | — | Upgrade bind9-develUpgrade bind910Upgrade bind99Upgrade bind911 | Dec 10, 2025 | Aug 6, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jul 19, 2016 |
| Hpux | — | Update NameService.BIND-RUN to the latest versionUpdate NameService.BIND-AUX to the latest version | Aug 11, 2017 | Jul 19, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bind-libsUpgrade bindUpgrade bind-licenseUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-libs-lite | Nov 30, 2017 | Jul 19, 2016 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory13 | Nov 30, 2017 | Jul 19, 2016 |
| Oracle Solaris | — | Upgrade service/network/dns/bind to version 9.6.3.11.7-0.175.3.12.0.1.0 on Solaris 11.3Upgrade network/dns/bind to version 9.6.3.11.7-0.175.3.12.0.1.0 on Solaris 11.3 | May 29, 2017 | Jul 19, 2016 |
| Redhat_linux | — | Upgrade bind-licenseUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-develUpgrade bind-sdbUpgrade bindUpgrade bind-utilsNo solution existsUpgrade bind-debuginfoUpgrade bind-lite-develUpgrade bind-pkcs11-utilsUpgrade bind-develUpgrade bind-chrootUpgrade bind-sdb-chrootUpgrade bind-libs-liteUpgrade bind-pkcs11 | Aug 24, 2017 | Jul 19, 2016 |
| Redhat_linux_5 | — | No fixes or workaround suggested by the vendor | Nov 29, 2019 | Jul 19, 2016 |
| Suse | — | Upgrade liblwres160Upgrade bindUpgrade libisccfg160Upgrade bind-devel-32bitUpgrade bind-libs-32bitUpgrade bind-chrootenvUpgrade libirs-develUpgrade libisc1606Upgrade bind-libs-x86Upgrade python-bindUpgrade bind-docUpgrade libdns169Upgrade libisccfg1600Upgrade libdns1605Upgrade libisc166Upgrade libns1604Upgrade libisc166-32bitUpgrade libbind9-160Upgrade libisccc1600Upgrade libirs160Upgrade bind-utilsUpgrade libirs1601Upgrade libbind9-1600Upgrade python3-bindUpgrade libisccc160Upgrade bind-develUpgrade bind-libs | Apr 13, 2017 | Jul 19, 2016 |
| Ubuntu | — | Upgrade bind9 (Ubuntu Pro)Upgrade lwresd (Ubuntu Pro) | Nov 29, 2022 | Jul 19, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 19, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub