imPC@ndo IT

Tracker / CVE-2016-1285

CVE-2016-1285

Medium 6.8

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
isc bind
isc bind · 9.0.0 → 9.9.8
isc bind · 9.10.0 → 9.10.3
juniper junos
opensuse leap
opensuse opensuse
suse linux_enterprise_debuginfo
suse linux_enterprise_desktop
suse linux_enterprise_server
suse linux_enterprise_software_development_kit
suse manager
suse manager_proxy
suse openstack_cloud

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References