CVE-2015-8000
published 2015-12-16CVE-2015-8000: db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and…
PriorityP337medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
54.69%
98.9th percentile
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.9.5.dfsg-12.1 (bookworm) | bind9 1:9.9.5.dfsg-12.1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by DNS responses containing records with a malformed/incorrect class attribute; monitor for REQUIRE assertion failures in db.c within named logs as an indicator of exploitation attempts. ↗
- →Recursive resolvers are the primary high-risk targets; an attacker can trigger the crash by causing the resolver to request a record with a malformed class attribute (e.g., via a malicious authoritative server or cache poisoning vector). ↗
- →Authoritative servers performing recursive queries to resolve NS RRSET addresses are also at risk; monitor authentication enforcement on recursive queries as a compensating control indicator. ↗
- →The crash manifests as named daemon exit due to a REQUIRE assertion failure; correlate sudden named process termination with incoming DNS response traffic as a detection signal. ↗
- ·Affected versions are ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2; patching to these versions or later is required to remediate. ↗
- ·No workaround is available for hosts running named; only hosts not running named are not vulnerable. ↗
- ·Red Hat Enterprise Linux 4 will not receive a fix for this CVE. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_cisco6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-15:27.bind: BIND remote denial of service vulnerability
bsd_advisories·2015-12-16·CVSS 5.0
CVE-2015-8000 [MEDIUM] FreeBSD-SA-15:27.bind: BIND remote denial of service vulnerability
FreeBSD-SA-15:27.bind Security Advisory
The FreeBSD Project
Topic: BIND remote denial of service vulnerability
Category: contrib
Module: bind
Announced: 2015-12-16
Credits: ISC
Affects: FreeBSD 9.x
Corrected: 2015-12-16 06:10:05 UTC (stable/9, 9.3-STABLE)
2015-12-16 06:21:26 UTC (releng/9.3, 9.3-RELEASE-p32)
CVE Name: CVE-2015-8000
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server. The libdns
library is a library of DNS protocol support functions.
II. Problem Description
An error in the parsing of incoming responses allows some r
Red Hat
bind: responses with a malformed class attribute can trigger an assertion failure in db.c
vendor_redhat·2015-12-15·CVSS 5.0
CVE-2015-8000 [MEDIUM] CWE-20 bind: responses with a malformed class attribute can trigger an assertion failure in db.c
bind: responses with a malformed class attribute can trigger an assertion failure in db.c
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
A denial of service flaw was found in the way BIND processed certain records with malformed class attributes. A remote attacker could use this flaw to send a query to request a cached record with a malformed class attribute that would cause named functioning as an authoritative or recursive server to crash. Note: This issue affects authoritative servers as well as recursive servers, however authoritative servers are at limited risk if they perform authentication when making recursive queries to reso
Ubuntu
Bind vulnerability
vendor_ubuntu·2015-12-15
CVE-2015-8000 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled responses with malformed
class attributes. A remote attacker could use this issue to cause Bind to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Cisco
Cisco FirePOWER 7000 and Cisco FirePOWER 8000 Series Inspection Engine Stall Vulnerability
vendor_cisco·2015-09-25·CVSS 6.1
CVE-2015-6307 [MEDIUM] CWE-399 Cisco FirePOWER 7000 and Cisco FirePOWER 8000 Series Inspection Engine Stall Vulnerability
Cisco FirePOWER 7000 and Cisco FirePOWER 8000 Series Inspection Engine Stall Vulnerability
A vulnerability in FireSIGHT System Software for Cisco FirePOWER 7000 Series and Cisco FirePOWER 8000 Series devices could allow an unauthenticated, adjacent attacker to cause the inspection engine to stop processing packets. Depending on the affected system configuration, this may cause traffic not to be inspected or to be dropped.
The vulnerability is due to improper parsing of crafted packets. An attacker could exploit this vulnerability by sending crafted packets to the affected system.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must have access to the same broadcast or collision domain as the targeted device. This access r
Cisco
Cisco TelePresence MSE 8000 Series Cross-Site Request Forgery Vulnerability
vendor_cisco·2015-07-09·CVSS 6.8
CVE-2015-4258 [MEDIUM] CWE-352 Cisco TelePresence MSE 8000 Series Cross-Site Request Forgery Vulnerability
Cisco TelePresence MSE 8000 Series Cross-Site Request Forgery Vulnerability
A vulnerability in the Cisco TelePresence MSE 8000 Series could allow an unauthenticated, remote attacker to execute unwanted actions.
The vulnerability is due to insufficient cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the link.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not kno
Debian
CVE-2015-8000: bind9 - db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows...
vendor_debian·2015·CVSS 5.0
CVE-2015-8000 [MEDIUM] CVE-2015-8000: bind9 - db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows...
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
Scope: local
bookworm: resolved (fixed in 1:9.9.5.dfsg-12.1)
bullseye: resolved (fixed in 1:9.9.5.dfsg-12.1)
forky: resolved (fixed in 1:9.9.5.dfsg-12.1)
sid: resolved (fixed in 1:9.9.5.dfsg-12.1)
trixie: resolved (fixed in 1:9.9.5.dfsg-12.1)
GHSA
GHSA-6v2g-2pm7-w6q7: db
ghsa_unreviewed·2022-05-13
CVE-2015-8000 [MEDIUM] CWE-20 GHSA-6v2g-2pm7-w6q7: db
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
OSV
CVE-2015-8000: db
osv·2015-12-16·CVSS 5.0
CVE-2015-8000 [MEDIUM] CVE-2015-8000: db
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8000 bind99: bind: responses with a malformed class attribute can trigger an assertion failure in db.c [fedora-all]
bugzilla·2015-12-15·CVSS 5.0
CVE-2015-8000 [MEDIUM] CVE-2015-8000 bind99: bind: responses with a malformed class attribute can trigger an assertion failure in db.c [fedora-all]
CVE-2015-8000 bind99: bind: responses with a malformed class attribute can trigger an assertion failure in db.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c [fedora-all]
bugzilla·2015-12-15·CVSS 5.0
CVE-2015-8000 [MEDIUM] CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c [fedora-all]
CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c
bugzilla·2015-12-14·CVSS 5.0
CVE-2015-8000 [MEDIUM] CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c
CVE-2015-8000 bind: responses with a malformed class attribute can trigger an assertion failure in db.c
The following flaw, reported by ISC, was found in BIND version 9 (9.0.0 through 9.9.8, 9.10.0 through 9.10.3):
An error in the parsing of incoming responses allows some records with an incorrect class to be be accepted by BIND instead of being rejected as malformed. This can trigger a REQUIRE assertion failure when those records are subsequently cached. Intentional exploitation of this condition is possible and could be used as a denial-of-service vector against servers performing recursive queries.
An attacker who can cause a server to request a record with a malformed class attribute can use this bug to trigger a REQUIRE assertion in db.c, causing named to exit and denying service t
Bugzilla
CVE-2015-3026 icecast: NULL pointer dereference in stream_auth handler leading to DoS
bugzilla·2015-04-09·CVSS 5.0
CVE-2015-3026 [MEDIUM] CVE-2015-3026 icecast: NULL pointer dereference in stream_auth handler leading to DoS
CVE-2015-3026 icecast: NULL pointer dereference in stream_auth handler leading to DoS
A flaw was found in the client URL authentication handling code:
The bug can only be triggered if "stream_auth" is being used, for example:
/test.ogg
This means, that all installations that use a default configuration are NOT affected. The default configuration only uses . Neither are simple mountpoints affected that use .
A workaround, if installing an updated package is not possible, is to disable "stream_auth"and use instead.
As far as we understand the bug only leads to a simple remote denial of service. The underlying issue is a null pointer dereference. For clarity: No remote code execution should be possible, server just segfaults.
Proof of concept:
curl "http://example.org:8000/admin/
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174143.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174145.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174252.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174520.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.htmlhttp://marc.info/?l=bugtraq&m=145680832702035&w=2http://packetstormsecurity.com/files/134882/FreeBSD-Security-Advisory-BIND-Denial-Of-Service.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2655.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2656.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0079.htmlhttp://www.debian.org/security/2015/dsa-3420http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/79349http://www.securitytracker.com/id/1034418http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966http://www.ubuntu.com/usn/USN-2837-1https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04923105https://kb.isc.org/article/AA-01317https://kb.isc.org/article/AA-01380https://kb.isc.org/article/AA-01438http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174143.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174145.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174252.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174520.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.htmlhttp://marc.info/?l=bugtraq&m=145680832702035&w=2http://packetstormsecurity.com/files/134882/FreeBSD-Security-Advisory-BIND-Denial-Of-Service.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2655.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2656.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0079.htmlhttp://www.debian.org/security/2015/dsa-3420http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/79349http://www.securitytracker.com/id/1034418http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966http://www.ubuntu.com/usn/USN-2837-1https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04923105https://kb.isc.org/article/AA-01317https://kb.isc.org/article/AA-01380https://kb.isc.org/article/AA-01438
2015-12-16
Published