Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8864


named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.


Published

2016-11-02T17:59:00.187

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application isc bind < 9.9.9 Yes
Application isc bind < 9.10.4 Yes
Application isc bind 9.9.9 Yes
Application isc bind 9.9.9 Yes
Application isc bind 9.9.9 Yes
Application isc bind 9.9.9 Yes
Application isc bind 9.9.9 Yes
Application isc bind 9.9.9 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application netapp data_ontap_edge - Yes
Application netapp solidfire - Yes
Application netapp steelstore_cloud_integrated_storage - Yes
Operating System redhat enterprise_linux_desktop 5.0 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_eus 6.7 Yes
Operating System redhat enterprise_linux_eus 7.2 Yes
Operating System redhat enterprise_linux_eus 7.3 Yes
Operating System redhat enterprise_linux_eus 7.4 Yes
Operating System redhat enterprise_linux_eus 7.5 Yes
Operating System redhat enterprise_linux_eus 7.6 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_server 5.0 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 6.2 Yes
Operating System redhat enterprise_linux_server_aus 6.4 Yes
Operating System redhat enterprise_linux_server_aus 6.5 Yes
Operating System redhat enterprise_linux_server_aus 6.6 Yes
Operating System redhat enterprise_linux_server_aus 7.2 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_aus 7.7 Yes
Operating System redhat enterprise_linux_server_tus 6.5 Yes
Operating System redhat enterprise_linux_server_tus 6.6 Yes
Operating System redhat enterprise_linux_server_tus 7.2 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.7 Yes
Operating System redhat enterprise_linux_workstation 5.0 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Operating System debian debian_linux 8.0 Yes

References