CVE-2015-8461
published 2015-12-16CVE-2015-8461: Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
4.85%
91.4th percentile
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: race condition when handling socket errors can lead to an assertion failure in resolver.c
vendor_redhat·2015-12-15·CVSS 7.1
CVE-2015-8461 [HIGH] CWE-362 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c
bind: race condition when handling socket errors can lead to an assertion failure in resolver.c
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-8461: bind9 - Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10...
vendor_debian·2015·CVSS 7.1
CVE-2015-8461 [HIGH] CVE-2015-8461: bind9 - Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10...
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-h967-r8fq-h9x2: Race condition in resolver
ghsa_unreviewed·2022-05-14
CVE-2015-8461 [HIGH] CWE-362 GHSA-h967-r8fq-h9x2: Race condition in resolver
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c [fedora-23]
bugzilla·2015-12-15·CVSS 7.1
CVE-2015-8461 [HIGH] CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c [fedora-23]
CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c [fedora-23]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-23 tr
Bugzilla
CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c
bugzilla·2015-12-14·CVSS 7.1
CVE-2015-8461 [HIGH] CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c
CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c
The following flaw, reported by ISC, was found in BIND version 9 (9.9.8 through 9.9.8-P1, 9.9.8-S1 through 9.9.8-S2, 9.10.3 through 9.10.3-P1):
Beginning with the September 2015 maintenance releases 9.9.8 and 9.10.3, an error was introduced into BIND 9 which can cause a server to exit after encountering an INSIST assertion failure in resolver.c. This error was introduced with the following patch:
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commit;h=adbf81335b67be0cebdcf9f1f4fcb38ef4814f4d
An uncommonly occurring condition can cause affected servers to exit with an INSIST failure depending on the outcome of a race condition in resolver.c While difficult to exploit re
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174145.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174252.htmlhttp://www.securityfocus.com/bid/79347http://www.securitytracker.com/id/1034419http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966https://kb.isc.org/article/AA-01319https://kb.isc.org/article/AA-01380https://kb.isc.org/article/AA-01438http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174145.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174252.htmlhttp://www.securityfocus.com/bid/79347http://www.securitytracker.com/id/1034419http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966https://kb.isc.org/article/AA-01319https://kb.isc.org/article/AA-01380https://kb.isc.org/article/AA-01438
2015-12-16
Published