CVE-2015-8705
published 2016-01-20CVE-2015-8705: buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion…
PriorityP337high7CVSS 3.0
AVNACHPRNUINSUCLILAH
EPSS
7.72%
94.2th percentile
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.06.6MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:C
vendor_debian7.0LOW
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: crash when converting OPT resource records and ECS options to text format
vendor_redhat·2016-01-19·CVSS 7.0
CVE-2015-8705 [HIGH] bind: crash when converting OPT resource records and ECS options to text format
bind: crash when converting OPT resource records and ECS options to text format
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Mitigation: Disable debug logging in named.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-8705: bind9 - buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is ena...
vendor_debian·2015·CVSS 7.0
CVE-2015-8705 [HIGH] CVE-2015-8705: bind9 - buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is ena...
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-j4rq-g63g-h87j: buffer
ghsa_unreviewed·2022-05-14
CVE-2015-8705 [HIGH] CWE-20 GHSA-j4rq-g63g-h87j: buffer
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]
bugzilla·2016-01-19·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]
CVE-2015-8704 CVE-2015-8705 bind: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c
bugzilla·2016-01-18·CVSS 6.5
CVE-2015-8704 [MEDIUM] CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c
CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c
The following flaw in BIND was reported by ISC:
A buffer size check used to guard against overflow could cause named to exit with an INSIST failure In apl_42.c.
A server could exit due to an INSIST failure in apl_42.c when performing certain string formatting operations. Examples include (but may not be limited to):
Slaves using text-format db files could be vulnerable if receiving a malformed record in a zone transfer from their master.
Masters using text-format db files could be vulnerable if they accept a malformed record in a DDNS update message.
Recursive resolvers are potentially vulnerable when debug logging, if they are fed a deliberately malformed record by a malicious server.
A server which has cache
Bugzilla
CVE-2015-8705 bind: crash when converting OPT resource records and ECS options to text format
bugzilla·2016-01-18·CVSS 6.5
CVE-2015-8705 [MEDIUM] CVE-2015-8705 bind: crash when converting OPT resource records and ECS options to text format
CVE-2015-8705 bind: crash when converting OPT resource records and ECS options to text format
The following flaw in BIND was reported by ISC:
In versions of BIND 9.10, errors can occur when OPT pseudo-RR data or ECS options are formatted to text. In 9.10.3 through 9.10.3-P2, the issue may result in a REQUIRE assertion failure in buffer.c. In prior 9.10 versions, it may result in named crashing (such as with a segmentation fault) or other misbehavior due to a buffer overrun.
This issue can affect both authoritative and recursive servers if they are performing debug logging. (It may also crash related tools which use the same code, such as dig or delv.)
Mitigation:
Disable debug logging in named.
Discussion:
Acknowledgements:
Red Hat would like to thank ISC for reporting this issue.
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176564.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175977.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.securityfocus.com/bid/81314http://www.securitytracker.com/id/1034740https://kb.isc.org/article/AA-01336https://kb.isc.org/article/AA-01380https://security.gentoo.org/glsa/201610-07http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176564.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/175977.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.securityfocus.com/bid/81314http://www.securitytracker.com/id/1034740https://kb.isc.org/article/AA-01336https://kb.isc.org/article/AA-01380https://security.gentoo.org/glsa/201610-07
2016-01-20
Published