CVE-2012-5166
published 2012-10-10CVE-2012-5166: ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a…
PriorityP345high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
34.20%
98.2th percentile
ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg.P1-4.3 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.3 (bookworm) |
| debian | isc-dhcp | < bind9 1:9.8.1.dfsg.P1-4.3 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.3 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-12:06.bind: Multiple Denial of Service vulnerabilities with named(8)
bsd_advisories·2012-11-22·CVSS 7.8
CVE-2012-4244 [HIGH] FreeBSD-SA-12:06.bind: Multiple Denial of Service vulnerabilities with named(8)
FreeBSD-SA-12:06.bind Security Advisory
The FreeBSD Project
Topic: Multiple Denial of Service vulnerabilities with named(8)
Category: contrib
Module: bind
Announced: 2012-11-22
Affects: All supported versions of FreeBSD before 9.1-RC2.
Corrected: 2012-11-22 23:15:38 UTC (RELENG_7, 7.4-STABLE)
2012-11-22 22:52:15 UTC (RELENG_7_4, 7.4-RELEASE-p11)
2012-10-11 13:25:09 UTC (RELENG_8, 8.3-STABLE)
2012-11-22 22:52:15 UTC (RELENG_8_3, 8.3-RELEASE-p5)
2012-10-10 19:50:15 UTC (RELENG_9, 9.1-PRERELEASE)
2012-11-22 22:52:15 UTC (RELENG_9_0, 9.0-RELEASE-p5)
2012-11-22 22:52:15 UTC (RELENG_9_1, 9.1-RC1-p1)
2012-11-22 22:52:15 UTC (RELENG_9_1, 9.1-RC2-p1)
2012-11-22 22:52:15 UTC (RELENG_9_1, 9.1-RC3-p1)
CVE Name: CVE-2012-4244, CVE-2012-5166
For general information regarding FreeBSD Security Advisori
Ubuntu
Bind vulnerability
vendor_ubuntu·2012-10-10
CVE-2012-5166 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Jake Montgomery discovered that Bind incorrectly handled certain specific
combinations of RDATA. A remote attacker could use this flaw to cause Bind
to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Specially crafted DNS data can cause a lockup in named
vendor_redhat·2012-10-09·CVSS 7.8
CVE-2012-5166 [HIGH] bind: Specially crafted DNS data can cause a lockup in named
bind: Specially crafted DNS data can cause a lockup in named
ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
Debian
CVE-2012-5166: bind9 - ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and ...
vendor_debian·2012·CVSS 7.8
CVE-2012-5166 [HIGH] CVE-2012-5166: bind9 - ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and ...
ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.3)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.3)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-4.3)
sid: resolved (fixed in 1:9.8.1.dfsg.P1-4.3)
trixie: resolved (fixed in 1:9.8.1.dfsg.P1-4.3)
GHSA
GHSA-v7pj-79hf-f778: ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2012-5166 [HIGH] GHSA-v7pj-79hf-f778: ISC BIND 9
ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
OSV
CVE-2012-5166: ISC BIND 9
osv·2012-10-10·CVSS 7.8
CVE-2012-5166 [HIGH] CVE-2012-5166: ISC BIND 9
ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named [fedora-all]
bugzilla·2012-10-10·CVSS 7.8
CVE-2012-5166 [HIGH] CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named [fedora-all]
CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?ty
Bugzilla
CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named
bugzilla·2012-10-09·CVSS 7.8
CVE-2012-5166 [HIGH] CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named
CVE-2012-5166 bind: Specially crafted DNS data can cause a lockup in named
A flaw in ISC BIND was reported where, if specific combinations of RDATA are loaded into a nameserver, either via cache or an authoritative zone, a subsequent query for a related record will cause named to lock up.
This vulnerability can be exploited remotely against recursive servers by inducing them to query for records provided by an authoritative
server. It affects authoritative servers if one of the combinations of resource records is loaded from file, provided via zone transfer, or
submitted to a zone via dynamic update.
Once bind becomes locked-up due to the above issue, it will not respond to queries or control commands. Normal functionality can only be restored by restarting named.
Workaround:
Setting t
http://aix.software.ibm.com/aix/efixes/security/bind9_advisory5.aschttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090491.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090586.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00013.htmlhttp://osvdb.org/86118http://rhn.redhat.com/errata/RHSA-2012-1363.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1364.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1365.htmlhttp://secunia.com/advisories/50903http://secunia.com/advisories/50909http://secunia.com/advisories/50956http://secunia.com/advisories/51054http://secunia.com/advisories/51078http://secunia.com/advisories/51096http://secunia.com/advisories/51106http://secunia.com/advisories/51178http://support.apple.com/kb/HT5880http://www.debian.org/security/2012/dsa-2560http://www.ibm.com/support/docview.wss?uid=isg1IV30185http://www.ibm.com/support/docview.wss?uid=isg1IV30247http://www.ibm.com/support/docview.wss?uid=isg1IV30364http://www.ibm.com/support/docview.wss?uid=isg1IV30365http://www.ibm.com/support/docview.wss?uid=isg1IV30366http://www.ibm.com/support/docview.wss?uid=isg1IV30367http://www.ibm.com/support/docview.wss?uid=isg1IV30368http://www.isc.org/software/bind/advisories/cve-2012-5166http://www.mandriva.com/security/advisories?name=MDVSA-2012:162http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/55852http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://blogs.oracle.com/sunsecurity/entry/cve_2012_5166_denial_ofhttps://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://kb.isc.org/article/AA-00801https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19706http://aix.software.ibm.com/aix/efixes/security/bind9_advisory5.aschttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090491.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090586.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00013.htmlhttp://osvdb.org/86118http://rhn.redhat.com/errata/RHSA-2012-1363.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1364.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1365.htmlhttp://secunia.com/advisories/50903http://secunia.com/advisories/50909http://secunia.com/advisories/50956http://secunia.com/advisories/51054http://secunia.com/advisories/51078http://secunia.com/advisories/51096http://secunia.com/advisories/51106http://secunia.com/advisories/51178http://support.apple.com/kb/HT5880http://www.debian.org/security/2012/dsa-2560http://www.ibm.com/support/docview.wss?uid=isg1IV30185http://www.ibm.com/support/docview.wss?uid=isg1IV30247http://www.ibm.com/support/docview.wss?uid=isg1IV30364http://www.ibm.com/support/docview.wss?uid=isg1IV30365http://www.ibm.com/support/docview.wss?uid=isg1IV30366http://www.ibm.com/support/docview.wss?uid=isg1IV30367http://www.ibm.com/support/docview.wss?uid=isg1IV30368http://www.isc.org/software/bind/advisories/cve-2012-5166http://www.mandriva.com/security/advisories?name=MDVSA-2012:162http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/55852http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfhttps://blogs.oracle.com/sunsecurity/entry/cve_2012_5166_denial_ofhttps://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://kb.isc.org/article/AA-00801https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19706
2012-10-10
Published