named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Aix 6.1.9 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.1.3 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.1.4 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.2.0 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Aix 7.2.1 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Alpine Linux | — | Upgrade bind | Sep 20, 2017 | Nov 2, 2016 |
| Amazon_linux | — | Upgrade bind | Nov 19, 2016 | Nov 2, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 2, 2016 |
| Centos_linux | — | Upgrade bind-libs-liteUpgrade bind-libsUpgrade bind-debuginfoUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-sdbUpgrade bind-lite-develUpgrade bind-pkcs11-utilsUpgrade bind-sdb-chrootUpgrade bind-licenseUpgrade bind-develUpgrade bindUpgrade bind-pkcs11Upgrade bind-pkcs11-devel | Nov 14, 2016 | Nov 2, 2016 |
| Debian | — | Upgrade bind9 | Mar 31, 2017 | Nov 1, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Nov 3, 2016 | Nov 2, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 3, 2016 |
| Freebsd | — | Upgrade bind99Upgrade bind910Upgrade bind9-develUpgrade FreeBSDUpgrade bind911 | Nov 14, 2016 | Nov 2, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Nov 2, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bind-chrootUpgrade bindUpgrade bind-libs-liteUpgrade bind-utilsUpgrade bind-licenseUpgrade bind-libs | Nov 30, 2017 | Nov 2, 2016 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory14 | Nov 30, 2017 | Nov 2, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade service/network/dns/bind to version 9.6.3.11.9-0.175.3.15.0.1.0 on Solaris 11.3Upgrade network/dns/bind to version 9.6.3.11.9-0.175.3.15.0.1.0 on Solaris 11.3 | May 29, 2017 | Nov 2, 2016 |
| Oracle_linux | — | Upgrade bind-libsUpgrade bind-libbind-develUpgrade bind-develUpgrade caching-nameserverUpgrade bind-chrootUpgrade bind-lite-develUpgrade bind-licenseUpgrade bind-sdbUpgrade bindUpgrade bind97Upgrade bind-pkcs11Upgrade bind-libs-liteUpgrade bind-pkcs11-utilsUpgrade bind-utilsUpgrade bind97-libsUpgrade bind97-utilsUpgrade bind97-chrootUpgrade bind-pkcs11-develUpgrade bind97-develUpgrade bind-sdb-chrootUpgrade bind-pkcs11-libs | Nov 2, 2016 | Nov 1, 2016 |
| Redhat_linux | — | Upgrade bind-lite-develUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-debuginfoUpgrade bind-develUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-pkcs11Upgrade bind-sdb-chrootUpgrade bind-pkcs11-develNo solution existsUpgrade bind-licenseUpgrade bind-pkcs11-libsUpgrade bind-libs | Nov 4, 2016 | Nov 2, 2016 |
| Suse | — | Upgrade bind-libsUpgrade bind-develUpgrade libbind9-160Upgrade libisc166-32bitUpgrade bind-utilsUpgrade libisccc1600Upgrade bind-chrootenvUpgrade bind-libs-x86Upgrade libirs1601Upgrade libns1604Upgrade liblwres160Upgrade python3-bindUpgrade libisccc160Upgrade libisccfg1600Upgrade libdns1605Upgrade libirs-develUpgrade python-bindUpgrade libdns169Upgrade libisc1606Upgrade bind-devel-32bitUpgrade libisc166Upgrade bind-docUpgrade libirs160Upgrade libbind9-1600Upgrade bindUpgrade libisccfg160Upgrade bind-libs-32bit | Nov 2, 2016 | Nov 2, 2016 |
| Ubuntu | — | Upgrade bind9 | Jul 1, 2017 | Nov 1, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub