CVE-2012-5688
published 2012-12-06CVE-2012-5688: ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
10.90%
95.4th percentile
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.8.4.dfsg.P1-1 (bookworm) | bind9 1:9.8.4.dfsg.P1-1 (bookworm) |
| debian | isc-dhcp | < bind9 1:9.8.4.dfsg.P1-1 (bookworm) | bind9 1:9.8.4.dfsg.P1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-1 | 1:9.8.4.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-1 | 1:9.8.4.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-1 | 1:9.8.4.dfsg.P1-1 |
| isc | bind9 | >= 0 < 1:9.8.4.dfsg.P1-1 | 1:9.8.4.dfsg.P1-1 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-13:01.bind: BIND remote DoS with deliberately crafted DNS64 query
bsd_advisories·2013-02-19·CVSS 7.8
CVE-2012-5688 [HIGH] FreeBSD-SA-13:01.bind: BIND remote DoS with deliberately crafted DNS64 query
FreeBSD-SA-13:01.bind Security Advisory
The FreeBSD Project
Topic: BIND remote DoS with deliberately crafted DNS64 query
Category: contrib
Module: bind
Announced: 2013-02-19
Affects: FreeBSD 9.x and later
Corrected: 2013-01-08 09:05:09 UTC (stable/9, 9.1-STABLE)
2013-02-19 13:27:20 UTC (releng/9.0, 9.0-RELEASE-p6)
2013-02-19 13:27:20 UTC (releng/9.1, 9.1-RELEASE-p1)
CVE Name: CVE-2012-5688
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server.
DNS64 is an IPv6 transition mechanism that will return a synthesized
AAAA response even if t
Ubuntu
Bind vulnerability
vendor_ubuntu·2012-12-06
CVE-2012-5688 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled certain crafted queries
when DNS64 was enabled. A remote attacker could use this flaw to cause Bind
to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: DoS on servers using DNS64
vendor_redhat·2012-12-04·CVSS 7.8
CVE-2012-5688 [HIGH] bind: DoS on servers using DNS64
bind: DoS on servers using DNS64
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Statement: This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 4 and 5, nor the versions of bind97 as shipped with Red Hat Enterprise Linux 5, as they did not include support for DNS64.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-5688: bind9 - ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled,...
vendor_debian·2012·CVSS 7.8
CVE-2012-5688 [HIGH] CVE-2012-5688: bind9 - ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled,...
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Scope: local
bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.8.4.dfsg.P1-1)
forky: resolved (fixed in 1:9.8.4.dfsg.P1-1)
sid: resolved (fixed in 1:9.8.4.dfsg.P1-1)
trixie: resolved (fixed in 1:9.8.4.dfsg.P1-1)
GHSA
GHSA-vf43-m8wx-8xfh: ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2012-5688 [HIGH] CWE-20 GHSA-vf43-m8wx-8xfh: ISC BIND 9
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
OSV
CVE-2012-5688: ISC BIND 9
osv·2012-12-06·CVSS 7.8
CVE-2012-5688 [HIGH] CVE-2012-5688: ISC BIND 9
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5688 bind: DoS on servers using DNS64
bugzilla·2012-12-04·CVSS 7.8
CVE-2012-5688 [HIGH] CVE-2012-5688 bind: DoS on servers using DNS64
CVE-2012-5688 bind: DoS on servers using DNS64
It was reported that BIND versions 9.8.0 and higher suffered from a flaw in the DNS64 IPv6 transition mechanism. A crafted query could be sent to the server and cause it to crash with a REQUIRE assertion failure.
DNS64 support was added in BIND 9.8.0, so earlier versions are not affected by this flaw. As well, nameservers are only affected if DNS64 support is enabled via the "dns64" configuration statement in named.conf. This is not enabled in the default configuration provided by Red Hat Enterprise Linux 6 or Fedora.
External References:
https://kb.isc.org/article/AA-00828
Discussion:
Statement:
This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 4 and 5, nor the versions of bind97 as shipped with R
Bugzilla
CVE-2012-5688 bind: DoS on servers using DNS64 [fedora-all]
bugzilla·2012-12-04·CVSS 7.8
CVE-2012-5688 [HIGH] CVE-2012-5688 bind: DoS on servers using DNS64 [fedora-all]
CVE-2012-5688 bind: DoS on servers using DNS64 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supp
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1549.htmlhttp://support.apple.com/kb/HT5880http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004http://www.ubuntu.com/usn/USN-1657-1https://kb.isc.org/article/AA-00828http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1549.htmlhttp://support.apple.com/kb/HT5880http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004http://www.ubuntu.com/usn/USN-1657-1https://kb.isc.org/article/AA-00828
2012-12-06
Published