ALPINE-CVE-2016-8864 PUBLISHED CVSS 7.5 HIGH

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.3bind9.9.5-r0, *, *
Alpine:v3.2bind9.10.0-r0, 9.10.0_p1-r0, 9.10.0_p2-r0

Timeline

References

Open in Interactive Console →