Back

MEDIUM

bind: malformed packet containing multiple cookie options can trigger assertion failure

Published Mar 9, 2016

Description

resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of bind97 as shipped with Red Hat Enterprise Linux 5 and bind as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include support for DNS cookies.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 9, 2016
Updated Aug 5, 2024
Reserved Jan 27, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 9, 2016