CVE-2016-2776
Low
Low
Medium
High
Critical
CVSS Score
Vulnerability Description
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Known Affected Software
15 configuration(s) from 3 vendor(s)
hp-ux
Version:
11.31
CPE:
cpe:2.3:o:hp:hp-ux:11.31:*:*:*:*:*:*:*
bind
Version:
9.10.0
CPE:
cpe:2.3:a:isc:bind:9.10.0:-:*:*:*:*:*:*
bind
Version:
9.11.0
CPE:
cpe:2.3:a:isc:bind:9.11.0:-:*:*:*:*:*:*
bind
Version:
9.10.2
CPE:
cpe:2.3:a:isc:bind:9.10.2:-:*:*:*:*:*:*
bind
Version:
9.10.4
CPE:
cpe:2.3:a:isc:bind:9.10.4:-:*:*:*:*:*:*
bind
Version:
9.10.1
CPE:
cpe:2.3:a:isc:bind:9.10.1:-:*:*:*:*:*:*
bind
Version:
9.10.3
CPE:
cpe:2.3:a:isc:bind:9.10.3:-:*:*:*:*:*:*
vm_server
Version:
3.2
CPE:
cpe:2.3:a:oracle:vm_server:3.2:*:*:*:*:*:x86:*
solaris
Version:
11.3
CPE:
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
linux
Version:
5.0
CPE:
cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*
vm_server
Version:
3.3
CPE:
cpe:2.3:a:oracle:vm_server:3.3:*:*:*:*:*:x86:*
linux
Version:
7
CPE:
cpe:2.3:o:oracle:linux:7:8:*:*:*:*:*:*
vm_server
Version:
3.4
CPE:
cpe:2.3:o:oracle:vm_server:3.4:*:*:*:*:*:*:*
linux
Version:
6
CPE:
cpe:2.3:o:oracle:linux:6:10:*:*:*:*:*:*
solaris
Version:
10.0
CPE:
cpe:2.3:o:oracle:solaris:10.0:*:*:*:*:*:*:*
This vulnerability affects 15 software configuration(s). Ensure you patch all affected systems.
References & Resources
-
http://rhn.redhat.com/errata/RHSA-2016-1944.htmlcve@mitre.org
-
http://rhn.redhat.com/errata/RHSA-2016-1945.htmlcve@mitre.org
-
http://rhn.redhat.com/errata/RHSA-2016-2099.htmlcve@mitre.org
-
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlcve@mitre.org Third Party Advisory
-
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlcve@mitre.org Third Party Advisory
-
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlcve@mitre.org Third Party Advisory
-
http://www.securityfocus.com/bid/93188cve@mitre.org
-
http://www.securitytracker.com/id/1036903cve@mitre.org
-
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107cve@mitre.org Third Party Advisory
-
https://kb.isc.org/article/AA-01419/0cve@mitre.org Vendor Advisory
-
https://kb.isc.org/article/AA-01435cve@mitre.org
-
https://kb.isc.org/article/AA-01436cve@mitre.org
-
https://kb.isc.org/article/AA-01438cve@mitre.org
-
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:28.bind.asccve@mitre.org
-
https://security.gentoo.org/glsa/201610-07cve@mitre.org
-
https://security.netapp.com/advisory/ntap-20160930-0001/cve@mitre.org
-
https://www.exploit-db.com/exploits/40453/cve@mitre.org
-
http://rhn.redhat.com/errata/RHSA-2016-1944.htmlaf854a3a-2127-422b-91ae-364da2661108
-
http://rhn.redhat.com/errata/RHSA-2016-1945.htmlaf854a3a-2127-422b-91ae-364da2661108
-
http://rhn.redhat.com/errata/RHSA-2016-2099.htmlaf854a3a-2127-422b-91ae-364da2661108
-
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlaf854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlaf854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlaf854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
http://www.securityfocus.com/bid/93188af854a3a-2127-422b-91ae-364da2661108
-
http://www.securitytracker.com/id/1036903af854a3a-2127-422b-91ae-364da2661108
-
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://kb.isc.org/article/AA-01419/0af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
-
https://kb.isc.org/article/AA-01435af854a3a-2127-422b-91ae-364da2661108
-
https://kb.isc.org/article/AA-01436af854a3a-2127-422b-91ae-364da2661108
-
https://kb.isc.org/article/AA-01438af854a3a-2127-422b-91ae-364da2661108
-
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:28.bind.ascaf854a3a-2127-422b-91ae-364da2661108
-
https://security.gentoo.org/glsa/201610-07af854a3a-2127-422b-91ae-364da2661108
-
https://security.netapp.com/advisory/ntap-20160930-0001/af854a3a-2127-422b-91ae-364da2661108
-
https://www.exploit-db.com/exploits/40453/af854a3a-2127-422b-91ae-364da2661108
Severity Details
out of 10.0
Low
Weakness Type (CWE)
CWE-20
Top 25 #14
Improper Input Validation
- Description
- The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- Exploit Likelihood
- High
- Typical Severity
- High
- Abstraction Level
- Class
Key Information
- Published Date
- September 28, 2016
