Tracker / CVE-2016-1285
CVE-2016-1285
Medium 6.8
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| fedoraproject | fedora |
| isc | bind |
| isc | bind · 9.0.0 → 9.9.8 |
| isc | bind · 9.10.0 → 9.10.3 |
| juniper | junos |
| opensuse | leap |
| opensuse | opensuse |
| suse | linux_enterprise_debuginfo |
| suse | linux_enterprise_desktop |
| suse | linux_enterprise_server |
| suse | linux_enterprise_software_development_kit |
| suse | manager |
| suse | manager_proxy |
| suse | openstack_cloud |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.