Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.810976
Kategorie:Denial of Service
Titel:ISC BIND DNS64 Denial of Service Vulnerability - Linux
Zusammenfassung:ISC BIND is prone to a denial of service vulnerability.
Beschreibung:Summary:
ISC BIND is prone to a denial of service vulnerability.

Vulnerability Insight:
The flaw exists due to improper
handling of queries when server is configured to use DNS64 and if the
option 'break-dnssec yes' is in use.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to cause a denial-of-service of a server.

Affected Software/OS:
ISC BIND 9.8.0 through 9.8.8-P1, 9.9.0
through 9.9.9-P6, 9.9.10b1 through 9.9.10rc1, 9.10.0 through 9.10.4-P6,
9.10.5b1 through 9.10.5rc1, 9.11.0 through 9.11.0-P3, 9.11.1b1 through
9.11.1rc1, 9.9.3-S1 through 9.9.9-S8.

Solution:
Update to ISC BIND version 9.9.9-P8
or 9.9.10rc3 or 9.10.5rc3 or 9.11.1rc3 or 9.9.9-S10 or 9.10.4-P8 or
9.11.0-P5 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-3136
BugTraq ID: 97653
http://www.securityfocus.com/bid/97653
Debian Security Information: DSA-3854 (Google Search)
https://www.debian.org/security/2017/dsa-3854
https://security.gentoo.org/glsa/201708-01
RedHat Security Advisories: RHSA-2017:1095
https://access.redhat.com/errata/RHSA-2017:1095
RedHat Security Advisories: RHSA-2017:1105
https://access.redhat.com/errata/RHSA-2017:1105
http://www.securitytracker.com/id/1038259
SuSE Security Announcement: openSUSE-SU-2020:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
SuSE Security Announcement: openSUSE-SU-2020:1701 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.