cbcvebase.
CVE-2016-2775
published 2016-07-19

CVE-2016-2775: ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to…

PriorityP346medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
63.35%
99.1th percentile
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.10.3.dfsg.P4-11 (bookworm)bind9 1:9.10.3.dfsg.P4-11 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
hphp-ux
iscbind
iscbind
iscbind
iscbind9.0 – 9.9.8
iscbind9.10.0 – 9.10.3
iscbind9>= 0 < 1:9.10.3.dfsg.P4-111:9.10.3.dfsg.P4-11
iscbind9>= 0 < 1:9.10.3.dfsg.P4-111:9.10.3.dfsg.P4-11
iscbind9>= 0 < 1:9.10.3.dfsg.P4-111:9.10.3.dfsg.P4-11
iscbind9>= 0 < 1:9.10.3.dfsg.P4-111:9.10.3.dfsg.P4-11
iscbind9>= 0 < 1:9.9.5.dfsg-3ubuntu0.19+esm91:9.9.5.dfsg-3ubuntu0.19+esm9
iscbind9>= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.19+esm51:9.10.3.dfsg.P4-8ubuntu1.19+esm5
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered when lwresd or the named lwres option is enabled and a long/oversized query name is sent via the lightweight resolver protocol (lwres). Monitor for abnormally large lwres protocol requests that could cause a segmentation fault or daemon crash in lwresd/named.
  • The crash occurs when a query name combined with a search list entry exceeds the maximum allowable length, triggering infinite recursion. Detect oversized DNS query names sent to the lwres listener port (default TCP/UDP 921).
  • If lwres lightweight resolver protocol is configured to accept remote client connections, any remote attacker can trigger the DoS. Audit named.conf for the presence of the 'lwres' statement or running lwresd processes as an exposure indicator.
  • ·The vulnerability only affects BIND instances where lwresd is running or the 'lwres' option is enabled in named.conf. Instances without this configuration are not affected.
  • ·Affected versions are ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2. Patched versions are not vulnerable.

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.