named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Aix 6.1.9 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.1.3 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.1.4 Bind_advisory14 | — | — | Dec 19, 2016 | Nov 2, 2016 |
| Aix 7.2.0 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Aix 7.2.1 Bind_advisory14 | — | — | Nov 2, 2017 | Nov 2, 2016 |
| Alpine Linux | — | Upgrade bind | Sep 20, 2017 | Nov 2, 2016 |
| Amazon_linux | — | Upgrade bind | Nov 19, 2016 | Nov 2, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 2, 2016 |
| Centos_linux | — | Upgrade bind-pkcs11-develUpgrade bindUpgrade bind-pkcs11-utilsUpgrade bind-licenseUpgrade bind-sdb-chrootUpgrade bind-pkcs11Upgrade bind-develUpgrade bind-sdbUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-debuginfoUpgrade bind-utilsUpgrade bind-chroot | Nov 14, 2016 | Nov 2, 2016 |
| Debian | — | Upgrade bind9 | Mar 31, 2017 | Nov 1, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Nov 3, 2016 | Nov 2, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 3, 2016 |
| Freebsd | — | Upgrade bind99Upgrade bind910Upgrade bind911Upgrade bind9-develUpgrade FreeBSD | Nov 14, 2016 | Nov 2, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Nov 2, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bindUpgrade bind-libs-liteUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-licenseUpgrade bind-libs | Nov 30, 2017 | Nov 2, 2016 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory14 | Nov 30, 2017 | Nov 2, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade service/network/dns/bind to version 9.6.3.11.9-0.175.3.15.0.1.0 on Solaris 11.3Upgrade network/dns/bind to version 9.6.3.11.9-0.175.3.15.0.1.0 on Solaris 11.3 | May 29, 2017 | Nov 2, 2016 |
| Oracle_linux | — | Upgrade bind-develUpgrade bind-pkcs11-utilsUpgrade bindUpgrade caching-nameserverUpgrade bind-chrootUpgrade bind-pkcs11Upgrade bind-lite-develUpgrade bind-libsUpgrade bind-sdbUpgrade bind-licenseUpgrade bind-libbind-develUpgrade bind97Upgrade bind-libs-liteUpgrade bind97-libsUpgrade bind-sdb-chrootUpgrade bind97-develUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-develUpgrade bind97-chrootUpgrade bind-utilsUpgrade bind97-utils | Nov 2, 2016 | Nov 1, 2016 |
| Redhat_linux | — | Upgrade bind-utilsUpgrade bindUpgrade bind-sdbUpgrade bind-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-develUpgrade bind-pkcs11Upgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-pkcs11-libsNo solution existsUpgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bind-sdb-chroot | Nov 4, 2016 | Nov 2, 2016 |
| Suse | — | Upgrade libirs160Upgrade libisccfg160Upgrade bind-libs-32bitUpgrade bind-docUpgrade libirs-develUpgrade libbind9-1600Upgrade libdns169Upgrade libisc166Upgrade libisc1606Upgrade bindUpgrade python-bindUpgrade bind-devel-32bitUpgrade libisccc160Upgrade libisccfg1600Upgrade libns1604Upgrade libirs1601Upgrade bind-libs-x86Upgrade bind-libsUpgrade libdns1605Upgrade bind-develUpgrade libisccc1600Upgrade bind-chrootenvUpgrade libbind9-160Upgrade libisc166-32bitUpgrade bind-utilsUpgrade liblwres160Upgrade python3-bind | Nov 2, 2016 | Nov 2, 2016 |
| Ubuntu | — | Upgrade bind9 | Jul 1, 2017 | Nov 1, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub