named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Aix 6.1.9 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.1.3 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.1.4 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.2.0 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Aix 7.2.1 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Alpine Linux | — | Upgrade bind | Sep 20, 2017 | Nov 2, 2016 |
| Amazon_linux | — | Upgrade bind | Nov 19, 2016 | Nov 2, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 2, 2016 |
| Centos_linux | — | Upgrade bind-pkcs11-libsUpgrade bind-sdbUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-debuginfoUpgrade bind-chrootUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-develUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-develUpgrade bind-pkcs11Upgrade bind-licenseUpgrade bind-sdb-chrootUpgrade bind | Nov 14, 2016 | Nov 2, 2016 |
| Debian | — | Upgrade bind9 | Mar 31, 2017 | Nov 1, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Nov 3, 2016 | Nov 2, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 3, 2016 |
| Freebsd | — | Upgrade bind911Upgrade bind9-develUpgrade bind910Upgrade FreeBSDUpgrade bind99 | Nov 14, 2016 | Nov 2, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Nov 2, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bind-utilsUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bindUpgrade bind-licenseUpgrade bind-libs | Nov 30, 2017 | Nov 2, 2016 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory14 | Nov 30, 2017 | Nov 2, 2016 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.6.3.11.9-0.175.3.15.0.1.0 on Solaris 11.3Upgrade service/network/dns/bind to version 9.6.3.11.9-0.175.3.15.0.1.0 on Solaris 11.3Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | May 29, 2017 | Nov 2, 2016 |
| Oracle_linux | — | Upgrade bind-sdb-chrootUpgrade bind97-utilsUpgrade bind-pkcs11-develUpgrade bind97-develUpgrade bind-utilsUpgrade bind97-chrootUpgrade bind-pkcs11-libsUpgrade bind97-libsUpgrade bind97Upgrade bind-licenseUpgrade caching-nameserverUpgrade bind-chrootUpgrade bindUpgrade bind-sdbUpgrade bind-libsUpgrade bind-lite-develUpgrade bind-libbind-develUpgrade bind-libs-liteUpgrade bind-pkcs11-utilsUpgrade bind-develUpgrade bind-pkcs11 | Nov 2, 2016 | Nov 1, 2016 |
| Redhat_linux | — | Upgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-pkcs11Upgrade bind-lite-develUpgrade bindUpgrade bind-develUpgrade bind-debuginfoUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-licenseUpgrade bind-sdb-chrootNo solution existsUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-devel | Nov 4, 2016 | Nov 2, 2016 |
| Suse | — | Upgrade libirs160Upgrade bind-docUpgrade bind-devel-32bitUpgrade bind-libs-32bitUpgrade bindUpgrade libirs-develUpgrade libisc166Upgrade libisc1606Upgrade python-bindUpgrade libisccfg160Upgrade libdns169Upgrade libbind9-1600Upgrade liblwres160Upgrade bind-libs-x86Upgrade libisc166-32bitUpgrade libisccc160Upgrade bind-libsUpgrade libisccc1600Upgrade python3-bindUpgrade libirs1601Upgrade bind-utilsUpgrade bind-develUpgrade libisccfg1600Upgrade libdns1605Upgrade libns1604Upgrade bind-chrootenvUpgrade libbind9-160 | Nov 2, 2016 | Nov 2, 2016 |
| Ubuntu | — | Upgrade bind9 | Jul 1, 2017 | Nov 1, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub