CVE-2015-8704Improper Input Validation in Bind

Severity
6.5MEDIUMNVD
EPSS
20.8%
top 4.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateMay 14

Description

apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Debianisc/bind9< 1:9.10.3.dfsg.P4-6+3
NVDisc/bind35 versions+34

🔴Vulnerability Details

3
GHSA
GHSA-9pc9-w372-6q8j: apl_422022-05-14
CVEList
CVE-2015-8704: apl_422016-01-20
OSV
CVE-2015-8704: apl_422016-01-20

📋Vendor Advisories

4
BSD
FreeBSD-SA-16:08.bind: BIND remote denial of service vulnerability2016-01-27
Red Hat
bind: specific APL data could trigger an INSIST in apl_42.c2016-01-19
Ubuntu
Bind vulnerability2016-01-19
Debian
CVE-2015-8704: bind9 - apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 all...2015

💬Community

3
Bugzilla
CVE-2015-8704 bind99: bind: specific APL data could trigger an INSIST in apl_42.c [fedora-all]2016-01-19
Bugzilla
CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]2016-01-19
Bugzilla
CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c2016-01-18
CVE-2015-8704 — Improper Input Validation in ISC Bind | cvebase