CVE-2012-4244Reachable Assertion in Bind

10 documents9 sources
Severity
7.8HIGHNVD
EPSS
58.3%
top 1.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14
Latest updateMay 17

Description

ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

Debianisc/bind9< 1:9.8.4.dfsg-1+3
NVDisc/bind55 versions+54

🔴Vulnerability Details

3
GHSA
GHSA-hrmx-gwc2-vh68: ISC BIND 92022-05-17
OSV
CVE-2012-4244: ISC BIND 92012-09-14
CVEList
CVE-2012-4244: ISC BIND 92012-09-14

📋Vendor Advisories

4
BSD
FreeBSD-SA-12:06.bind: Multiple Denial of Service vulnerabilities with named(8)2012-11-22
Ubuntu
Bind vulnerability2012-09-13
Red Hat
bind: specially crafted resource record causes named to exit2012-09-12
Debian
CVE-2012-4244: bind9 - ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and ...2012

💬Community

2
Bugzilla
CVE-2012-4244 bind: specially crafted resource record causes named to exit [fedora-all]2012-09-12
Bugzilla
CVE-2012-4244 bind: specially crafted resource record causes named to exit2012-09-12
CVE-2012-4244 — Reachable Assertion in ISC Bind | cvebase