cbcvebase.
CVE-2016-1286
published 2016-03-09

CVE-2016-1286: named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via…

PriorityP358high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
62.10%
99.1th percentile
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbind9< bind9 1:9.10.3.dfsg.P4-6 (bookworm)bind9 1:9.10.3.dfsg.P4-6 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
iscbind
iscbind
iscbind>= 9.0.0 < 9.9.89.9.8
iscbind>= 9.10.0 < 9.10.39.10.3
iscbind9>= 0 < 1:9.10.3.dfsg.P4-61:9.10.3.dfsg.P4-6
iscbind9>= 0 < 1:9.10.3.dfsg.P4-61:9.10.3.dfsg.P4-6
iscbind9>= 0 < 1:9.10.3.dfsg.P4-61:9.10.3.dfsg.P4-6
iscbind9>= 0 < 1:9.10.3.dfsg.P4-61:9.10.3.dfsg.P4-6
iscbind9>= 0 < 1:9.9.5.dfsg-3ubuntu0.81:9.9.5.dfsg-3ubuntu0.8
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2016-1286 triggers an assertion failure in resolver.c or db.c when named parses a signature record (RRSIG) covering a DNAME record type in a recursive DNS response. Detection should focus on DNS responses containing an RRSIG record whose type-covered field is DNAME while the actual answer RR is of a different type.
  • The attack pattern is: a DNS response contains an answer RR of any type other than DNAME, followed by an RRSIG record whose type-covered field is DNAME. This combination should be flagged in DNS traffic inspection.
  • Fortinet IPS signature 'ISC.BIND.DNAME.Resource.Records.Parsing.DoS' can be used as a reference signature name for building equivalent detection rules in other IPS/IDS platforms.
  • ·Only BIND 9.x versions before 9.9.8-P4 and 9.10.x versions before 9.10.3-P4 are vulnerable; patched versions are not affected.
  • ·The vulnerability is triggered via a crafted DNS *response* received by the BIND server (not a direct inbound query to the victim), so attack traffic originates from an attacker-controlled authoritative server upstream of the recursive resolver.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.