cbcvebase.
CVE-2015-8000
published 2015-12-16

CVE-2015-8000: db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and…

PriorityP337medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
54.69%
98.9th percentile
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.

Affected

75 ranges· showing 25
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.9.5.dfsg-12.1 (bookworm)bind9 1:9.9.5.dfsg-12.1 (bookworm)
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by DNS responses containing records with a malformed/incorrect class attribute; monitor for REQUIRE assertion failures in db.c within named logs as an indicator of exploitation attempts.
  • Recursive resolvers are the primary high-risk targets; an attacker can trigger the crash by causing the resolver to request a record with a malformed class attribute (e.g., via a malicious authoritative server or cache poisoning vector).
  • Authoritative servers performing recursive queries to resolve NS RRSET addresses are also at risk; monitor authentication enforcement on recursive queries as a compensating control indicator.
  • The crash manifests as named daemon exit due to a REQUIRE assertion failure; correlate sudden named process termination with incoming DNS response traffic as a detection signal.
  • ·Affected versions are ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2; patching to these versions or later is required to remediate.
  • ·No workaround is available for hosts running named; only hosts not running named are not vulnerable.
  • ·Red Hat Enterprise Linux 4 will not receive a fix for this CVE.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_cisco6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.