CVE-2015-8704
published 2016-01-20CVE-2015-8704: apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion…
PriorityP337medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
20.33%
97.2th percentile
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-6 (bookworm) | bind9 1:9.10.3.dfsg.P4-6 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-16:08.bind: BIND remote denial of service vulnerability
bsd_advisories·2016-01-27·CVSS 6.5
CVE-2015-8704 [MEDIUM] FreeBSD-SA-16:08.bind: BIND remote denial of service vulnerability
FreeBSD-SA-16:08.bind Security Advisory
The FreeBSD Project
Topic: BIND remote denial of service vulnerability
Category: contrib
Module: bind
Announced: 2016-01-27
Credits: ISC
Affects: FreeBSD 9.x
Corrected: 2016-01-20 08:54:35 UTC (stable/9, 9.3-STABLE)
2016-01-27 07:42:11 UTC (releng/9.3, 9.3-RELEASE-p35)
CVE Name: CVE-2015-8704
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server.
Address Prefixes List (APL RR) is a type of DNS Resource Record defined in
RFC 3123.
II. Problem Description
There is an off-by-one error in a buffer
Red Hat
bind: specific APL data could trigger an INSIST in apl_42.c
vendor_redhat·2016-01-19·CVSS 6.5
CVE-2015-8704 [MEDIUM] CWE-20 bind: specific APL data could trigger an INSIST in apl_42.c
bind: specific APL data could trigger an INSIST in apl_42.c
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
A denial of service flaw was found in the way BIND processed certain malformed Address Prefix List (APL) records. A remote, authenticated attacker could use this flaw to cause named to crash.
Ubuntu
Bind vulnerability
vendor_ubuntu·2016-01-19
CVE-2015-8704 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled certain APL data. A remote
attacker could possibly use this issue to cause Bind to crash, resulting in
a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-8704: bind9 - apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 all...
vendor_debian·2015·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704: bind9 - apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 all...
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-6)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-6)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-6)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-6)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-6)
GHSA
GHSA-9pc9-w372-6q8j: apl_42
ghsa_unreviewed·2022-05-14
CVE-2015-8704 [MEDIUM] CWE-20 GHSA-9pc9-w372-6q8j: apl_42
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
OSV
CVE-2015-8704: apl_42
osv·2016-01-20·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704: apl_42
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8704 bind99: bind: specific APL data could trigger an INSIST in apl_42.c [fedora-all]
bugzilla·2016-01-19·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704 bind99: bind: specific APL data could trigger an INSIST in apl_42.c [fedora-all]
CVE-2015-8704 bind99: bind: specific APL data could trigger an INSIST in apl_42.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]
bugzilla·2016-01-19·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]
CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c
bugzilla·2016-01-18·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c
CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c
The following flaw in BIND was reported by ISC:
A buffer size check used to guard against overflow could cause named to exit with an INSIST failure In apl_42.c.
A server could exit due to an INSIST failure in apl_42.c when performing certain string formatting operations. Examples include (but may not be limited to):
Slaves using text-format db files could be vulnerable if receiving a malformed record in a zone transfer from their master.
Masters using text-format db files could be vulnerable if they accept a malformed record in a DDNS update message.
Recursive resolvers are potentially vulnerable when debug logging, if they are fed a deliberately malformed record by a malicious server.
A server which has cache
Bugzilla
CVE-2015-8705 bind: crash when converting OPT resource records and ECS options to text format
bugzilla·2016-01-18·CVSS 6.5
CVE-2015-8705 [MEDIUM] CVE-2015-8705 bind: crash when converting OPT resource records and ECS options to text format
CVE-2015-8705 bind: crash when converting OPT resource records and ECS options to text format
The following flaw in BIND was reported by ISC:
In versions of BIND 9.10, errors can occur when OPT pseudo-RR data or ECS options are formatted to text. In 9.10.3 through 9.10.3-P2, the issue may result in a REQUIRE assertion failure in buffer.c. In prior 9.10 versions, it may result in named crashing (such as with a segmentation fault) or other misbehavior due to a buffer overrun.
This issue can affect both authoritative and recursive servers if they are performing debug logging. (It may also crash related tools which use the same code, such as dig or delv.)
Mitigation:
Disable debug logging in named.
Discussion:
Acknowledgements:
Red Hat would like to thank ISC for reporting this issue.
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176564.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178045.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175973.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175977.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.htmlhttp://marc.info/?l=bugtraq&m=145680832702035&w=2http://rhn.redhat.com/errata/RHSA-2016-0073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0074.htmlhttp://www.debian.org/security/2016/dsa-3449http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/81329http://www.securitytracker.com/id/1034739http://www.ubuntu.com/usn/USN-2874-1https://kb.isc.org/article/AA-01335https://kb.isc.org/article/AA-01380https://kb.isc.org/article/AA-01438https://security.gentoo.org/glsa/201610-07https://www.freebsd.org/security/advisories/FreeBSD-SA-16:08.bind.aschttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176564.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178045.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175973.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175977.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.htmlhttp://marc.info/?l=bugtraq&m=145680832702035&w=2http://rhn.redhat.com/errata/RHSA-2016-0073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0074.htmlhttp://www.debian.org/security/2016/dsa-3449http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/81329http://www.securitytracker.com/id/1034739http://www.ubuntu.com/usn/USN-2874-1https://kb.isc.org/article/AA-01335https://kb.isc.org/article/AA-01380https://kb.isc.org/article/AA-01438https://security.gentoo.org/glsa/201610-07https://www.freebsd.org/security/advisories/FreeBSD-SA-16:08.bind.asc
2016-01-20
Published