cbcvebase.
CVE-2015-5722
published 2015-09-05

CVE-2015-5722: buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and…

high7.8CVSS 3.1
AVNACLAuNCNINAC
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

Affected

9 ranges
VendorProductVersion rangeFixed in
applemac_os_x_server
appleos_x_server
debianbind9< bind9 1:9.9.5.dfsg-12 (bookworm)bind9 1:9.9.5.dfsg-12 (bookworm)
iscbind<= 9.9.7
iscbind<= 9.10.2
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12

CVSS provenance

nvd7.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH