CVE-2016-8864
high-risk
Published 2016-11-02
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
Do I need to act?
!
45.4% chance of exploitation in next 30 days
EPSS score — higher than 55% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
References (34)
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2141.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2142.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2615.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2871.html
Third Party Advisory
http://www.debian.org/security/2016/dsa-3703
Third Party Advisory
http://www.securityfocus.com/bid/94067
Third Party Advisory
http://www.securitytracker.com/id/1037156
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1583
Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c...
Vendor Advisory
https://kb.isc.org/article/AA-01434
Broken Link
https://kb.isc.org/article/AA-01435
Broken Link
https://kb.isc.org/article/AA-01436
Broken Link
https://kb.isc.org/article/AA-01437
Broken Link
https://kb.isc.org/article/AA-01438
Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:34.bind.asc
Third Party Advisory
https://security.gentoo.org/glsa/201701-26
Third Party Advisory
https://security.netapp.com/advisory/ntap-20180926-0005/
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2141.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2142.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2615.html
and 14 more references
69
/ 100
high-risk
Severity
26/34 · High
Exploitability
17/34 · Moderate
Exposure
26/34 · High