CVE-2015-5722
published 2015-09-05CVE-2015-5722: buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and…
PriorityP348high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
33.65%
98.2th percentile
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x_server | — | — |
| apple | os_x_server | — | — |
| debian | bind9 | < bind9 1:9.9.5.dfsg-12 (bookworm) | bind9 1:9.9.5.dfsg-12 (bookworm) |
| isc | bind | <= 9.9.7 | — |
| isc | bind | <= 9.10.2 | — |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-12 | 1:9.9.5.dfsg-12 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-12 | 1:9.9.5.dfsg-12 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-12 | 1:9.9.5.dfsg-12 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-12 | 1:9.9.5.dfsg-12 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the assertion failure in buffer.c within named (ISC BIND). A remote attacker triggers a crash by sending a DNS query that requires a response from a zone containing a malformed DNSSEC key, causing a failed assertion and daemon exit. ↗
- →Recursive resolvers performing DNSSEC validation are at greatest risk; monitor for unexpected named process crashes (assertion failures) especially when querying zones with DNSSEC keys. ↗
- →Affected BIND versions: 9.0.0 through 9.8.8, 9.9.0 through 9.9.7-P2, and 9.10.0 through 9.10.2-P3. Use version detection to identify vulnerable named instances. ↗
- ·No workaround is available for vulnerable BIND versions; the only mitigation is patching to 9.9.7-P3 or 9.10.2-P4 (or later). ↗
- ·Both validating resolvers (recursive) and authoritative servers can be affected if an attacker controls a zone the server must query, broadening the attack surface beyond just recursive resolvers. ↗
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q4fr-6j5h-39h7: buffer
ghsa_unreviewed·2022-05-17
CVE-2015-5722 [HIGH] CWE-20 GHSA-q4fr-6j5h-39h7: buffer
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
OSV
CVE-2015-5722: buffer
osv·2015-09-05·CVSS 7.8
CVE-2015-5722 [HIGH] CVE-2015-5722: buffer
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
BSD
FreeBSD-SA-15:23.bind: BIND remote denial of service vulnerability
bsd_advisories·2015-09-02·CVSS 7.8
CVE-2015-5722 [HIGH] FreeBSD-SA-15:23.bind: BIND remote denial of service vulnerability
FreeBSD-SA-15:23.bind Security Advisory
The FreeBSD Project
Topic: BIND remote denial of service vulnerability
Category: contrib
Module: bind
Announced: 2015-09-02
Credits: ISC
Affects: FreeBSD 9.x
Corrected: 2015-09-02 20:06:46 UTC (stable/9, 9.3-STABLE)
2015-09-02 20:07:03 UTC (releng/9.3, 9.3-RELEASE-p25)
CVE Name: CVE-2015-5722
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server. The libdns
library is a library of DNS protocol support functions.
II. Problem Description
Parsing a malformed DNSSEC key can cause a validating resol
Red Hat
bind: malformed DNSSEC key failed assertion denial of service
vendor_redhat·2015-09-02·CVSS 7.8
CVE-2015-5722 [HIGH] CWE-617 bind: malformed DNSSEC key failed assertion denial of service
bind: malformed DNSSEC key failed assertion denial of service
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
A denial of service flaw was found in the way BIND parsed certain malformed DNSSEC keys. A remote attacker could use this flaw to send a specially crafted DNS query (for example, a query requiring a response from a zone containing a deliberately malformed key) that would cause named functioning as a validating resolver to crash.
Package: bind (Red Hat Enterprise Linux 4) - Affected
Ubuntu
Bind vulnerability
vendor_ubuntu·2015-09-02
CVE-2015-5722 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Hanno Böck discovered that Bind incorrectly handled certain malformed keys
when configured to perform DNSSEC validation. A remote attacker could use
this issue with specially crafted zone data to cause Bind to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-5722: bind9 - buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 al...
vendor_debian·2015·CVSS 7.8
CVE-2015-5722 [HIGH] CVE-2015-5722: bind9 - buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 al...
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
Scope: local
bookworm: resolved (fixed in 1:9.9.5.dfsg-12)
bullseye: resolved (fixed in 1:9.9.5.dfsg-12)
forky: resolved (fixed in 1:9.9.5.dfsg-12)
sid: resolved (fixed in 1:9.9.5.dfsg-12)
trixie: resolved (fixed in 1:9.9.5.dfsg-12)
Apple
CVE-2015-5722: OS X Server 5.0.15
vendor_apple·CVSS 7.8
CVE-2015-5722 [HIGH] CVE-2015-5722: OS X Server 5.0.15
Apple Security Update: About the security content of OS X Server 5.0.15
Product: OS X Server
Version: 5.0.15
CVE: CVE-2015-5722
Component: CVE-ID
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5722 bind99: bind: malformed DNSSEC key failed assertion denial of service [fedora-22]
bugzilla·2015-09-03·CVSS 7.8
CVE-2015-5722 [HIGH] CVE-2015-5722 bind99: bind: malformed DNSSEC key failed assertion denial of service [fedora-22]
CVE-2015-5722 bind99: bind: malformed DNSSEC key failed assertion denial of service [fedora-22]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-22 tracking bug for bind99: see
Bugzilla
CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service [fedora-21]
bugzilla·2015-09-03·CVSS 7.8
CVE-2015-5722 [HIGH] CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service [fedora-21]
CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service [fedora-21]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-21 tracking bug for bind: see blocks bu
Bugzilla
CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service
bugzilla·2015-09-01·CVSS 7.8
CVE-2015-5722 [HIGH] CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service
CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service
The following flaw, reported by ISC, was found in all versions of BIND 9 (9.0.0 through 9.8.8, 9.9.0 through 9.9.7-P2, and 9.10.0 through 9.10.2-P3):
Parsing a malformed DNSSEC key can cause a validating resolver to exit
due to a failed assertion in buffer.c. It is possible for a remote
attacker to deliberately trigger this condition, for example by using a
query which requires a response from a zone containing a deliberately
malformed key.
ISC would like to thank Hanno Böck from the Fuzzing Project for
discovering and reporting this defect. We would also like to express
our appreciation to the developers of the American Fuzzy Lop tool, which
has been instrumental in revealing recently-disclosed vulnerabilities
http://lists.apple.com/archives/security-announce/2015/Oct/msg00009.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168686.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165750.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165810.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165996.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167465.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.htmlhttp://marc.info/?l=bugtraq&m=144294073801304&w=2http://rhn.redhat.com/errata/RHSA-2015-1705.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1706.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1707.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0079.htmlhttp://www.debian.org/security/2015/dsa-3350http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/76605http://www.securitytracker.com/id/1033452http://www.ubuntu.com/usn/USN-2728-1https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04891218https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04923105https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918https://kb.isc.org/article/AA-01287https://kb.isc.org/article/AA-01305https://kb.isc.org/article/AA-01306https://kb.isc.org/article/AA-01307https://kb.isc.org/article/AA-01438https://kc.mcafee.com/corporate/index?page=content&id=SB10134https://security.gentoo.org/glsa/201510-01https://security.netapp.com/advisory/ntap-20190730-0001/https://support.apple.com/HT205376http://lists.apple.com/archives/security-announce/2015/Oct/msg00009.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168686.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165750.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165810.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165996.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167465.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.htmlhttp://marc.info/?l=bugtraq&m=144294073801304&w=2http://rhn.redhat.com/errata/RHSA-2015-1705.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1706.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1707.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0079.htmlhttp://www.debian.org/security/2015/dsa-3350http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/76605http://www.securitytracker.com/id/1033452http://www.ubuntu.com/usn/USN-2728-1https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04891218https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04923105https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918https://kb.isc.org/article/AA-01287https://kb.isc.org/article/AA-01305https://kb.isc.org/article/AA-01306https://kb.isc.org/article/AA-01307https://kb.isc.org/article/AA-01438https://kc.mcafee.com/corporate/index?page=content&id=SB10134https://security.gentoo.org/glsa/201510-01https://security.netapp.com/advisory/ntap-20190730-0001/https://support.apple.com/HT205376
2015-09-05
Published