bind: assertion failure while handling responses containing a DNAME answer
Published Nov 2, 2016
7.5
HIGHCVSS 3.1
EPSS 38.73%
Description
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
Affected products
No data.
Configuration 1
- ≥ 9.0.0 · < 9.9.9
- ≥ 9.10.0 · < 9.10.4
- 9.9.9
- 9.9.9
- 9.9.9
- 9.9.9
- 9.9.9
- 9.9.9
- 9.10.4
- 9.10.4
- 9.10.4
- 9.10.4
- 9.10.4
- 9.10.4
- 9.10.4
- 9.11.0
- 9.11.0
- 9.11.0
- 9.11.0
- 9.11.0
- 9.11.0
- 9.11.0
Configuration 2
- n/a
- n/a
- n/a
Configuration 3
- 5.0
- 6.0
- 7.0
- 6.7
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 5.0
- 6.0
- 7.0
- 6.2
- 6.4
- 6.5
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 6.5
- 6.6
- 7.2
- 7.3
- 7.6
- 7.7
- 5.0
- 6.0
- 7.0
Configuration 4
- 8.0
No data.
Red Hat Enterprise Linux 5
bind-30:9.3.6-25.P1.el5_11.11
Fixed · RHSA-2016:2141
Red Hat Enterprise Linux 5
bind97-32:9.7.0-21.P2.el5_11.9
Fixed · RHSA-2016:2142
Red Hat Enterprise Linux 6
bind-32:9.8.2-0.47.rc1.el6_8.3
Fixed · RHSA-2016:2141
Red Hat Enterprise Linux 6.2 Advanced Update Support
bind-32:9.7.3-8.P3.el6_2.6
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 6.4 Advanced Update Support
bind-32:9.8.2-0.17.rc1.el6_4.10
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 6.5 Advanced Update Support
bind-32:9.8.2-0.23.rc1.el6_5.5
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 6.5 Telco Extended Update Support
bind-32:9.8.2-0.23.rc1.el6_5.5
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 6.6 Advanced Update Support
bind-32:9.8.2-0.30.rc1.el6_6.7
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
bind-32:9.8.2-0.30.rc1.el6_6.7
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 6.7 Extended Update Support
bind-32:9.8.2-0.37.rc1.el6_7.9
Fixed · RHSA-2016:2871
Red Hat Enterprise Linux 7
bind-32:9.9.4-38.el7_3
Fixed · RHSA-2016:2615
Red Hat Enterprise Linux 7.2 Extended Update Support
bind-32:9.9.4-29.el7_2.6
Fixed · RHSA-2017:1583
Red Hat Enterprise Linux 4
bind
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind-30:9.3.6-25.P1.el5_11.11 | Fixed | RHSA-2016:2141 |
| Red Hat Enterprise Linux 5 | bind97-32:9.7.0-21.P2.el5_11.9 | Fixed | RHSA-2016:2142 |
| Red Hat Enterprise Linux 6 | bind-32:9.8.2-0.47.rc1.el6_8.3 | Fixed | RHSA-2016:2141 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | bind-32:9.7.3-8.P3.el6_2.6 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | bind-32:9.8.2-0.17.rc1.el6_4.10 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | bind-32:9.8.2-0.23.rc1.el6_5.5 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | bind-32:9.8.2-0.23.rc1.el6_5.5 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | bind-32:9.8.2-0.30.rc1.el6_6.7 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | bind-32:9.8.2-0.30.rc1.el6_6.7 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | bind-32:9.8.2-0.37.rc1.el6_7.9 | Fixed | RHSA-2016:2871 |
| Red Hat Enterprise Linux 7 | bind-32:9.9.4-38.el7_3 | Fixed | RHSA-2016:2615 |
| Red Hat Enterprise Linux 7.2 Extended Update Support | bind-32:9.9.4-29.el7_2.6 | Fixed | RHSA-2017:1583 |
| Red Hat Enterprise Linux 4 | bind | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (21)
- http://rhn.redhat.com/errata/RHSA-2016-2141.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2142.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2615.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2871.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2016/dsa-3703 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/94067 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037156 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1583 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-8864 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1389652 Issue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05381687 x_refsource_CONFIRMThird Party Advisory
- https://kb.isc.org/article/AA-01434 x_refsource_CONFIRMVendor Advisory
- https://kb.isc.org/article/AA-01435 x_refsource_CONFIRMBroken Link
- https://kb.isc.org/article/AA-01436 x_refsource_CONFIRMBroken Link
- https://kb.isc.org/article/AA-01437 x_refsource_CONFIRMBroken Link
- https://kb.isc.org/article/AA-01438 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2016-8864
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:34.bind.asc vendor-advisoryx_refsource_FREEBSDThird Party Advisory
- https://security.gentoo.org/glsa/201701-26 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180926-0005/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-8864
Change history (0)
No recorded changes yet.