A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade bind | May 31, 2017 | May 8, 2017 |
| Centos_linux | — | Upgrade bind-libsUpgrade bind-utilsUpgrade bindUpgrade bind-chrootUpgrade bind-sdbUpgrade bind-debuginfoUpgrade bind-devel | May 10, 2017 | May 8, 2017 |
| Debian | — | Upgrade bind9 | Feb 19, 2019 | Feb 16, 2018 |
| Oracle_linux | — | Upgrade bind-libsUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-chrootUpgrade bindUpgrade bind-devel | May 8, 2017 | May 8, 2017 |
| Redhat_linux | — | Upgrade bind-debuginfoNo solution existsUpgrade bind-libsUpgrade bindUpgrade bind-sdbUpgrade bind-develUpgrade bind-utilsUpgrade bind-chroot | May 9, 2017 | May 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub