CVE-2016-2775
published 2016-07-19CVE-2016-2775: ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to…
PriorityP346medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
63.35%
99.1th percentile
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-11 (bookworm) | bind9 1:9.10.3.dfsg.P4-11 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| hp | hp-ux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.0 – 9.9.8 | — |
| isc | bind | 9.10.0 – 9.10.3 | — |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.19+esm9 | 1:9.9.5.dfsg-3ubuntu0.19+esm9 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.19+esm5 | 1:9.10.3.dfsg.P4-8ubuntu1.19+esm5 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered when lwresd or the named lwres option is enabled and a long/oversized query name is sent via the lightweight resolver protocol (lwres). Monitor for abnormally large lwres protocol requests that could cause a segmentation fault or daemon crash in lwresd/named. ↗
- →The crash occurs when a query name combined with a search list entry exceeds the maximum allowable length, triggering infinite recursion. Detect oversized DNS query names sent to the lwres listener port (default TCP/UDP 921). ↗
- →If lwres lightweight resolver protocol is configured to accept remote client connections, any remote attacker can trigger the DoS. Audit named.conf for the presence of the 'lwres' statement or running lwresd processes as an exposure indicator. ↗
- ·The vulnerability only affects BIND instances where lwresd is running or the 'lwres' option is enabled in named.conf. Instances without this configuration are not affected. ↗
- ·Affected versions are ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2. Patched versions are not vulnerable. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bind9 vulnerabilities
osv·2022-11-29·CVSS 5.9
CVE-2016-2775 [MEDIUM] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that Bind incorrectly handled large query name when using
lightweight resolver protocol. A remote attacker could use this issue to
consume resources, leading to a denial of service. (CVE-2016-2775)
It was discovered that Bind incorrectly handled large zone data size
received via AXFR response. A remote authenticated attacker could use this
issue to consume resources, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-6170)
GHSA
GHSA-c3hx-3ppq-fr4p: ISC BIND 9
ghsa_unreviewed·2022-05-13
CVE-2016-2775 [MEDIUM] CWE-20 GHSA-c3hx-3ppq-fr4p: ISC BIND 9
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
OSV
CVE-2016-2775: ISC BIND 9
osv·2016-07-19·CVSS 5.9
CVE-2016-2775 [MEDIUM] CVE-2016-2775: ISC BIND 9
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2022-11-29·CVSS 5.9
CVE-2016-2775 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
It was discovered that Bind incorrectly handled large query name when using
lightweight resolver protocol. A remote attacker could use this issue to
consume resources, leading to a denial of service. (CVE-2016-2775)
It was discovered that Bind incorrectly handled large zone data size
received via AXFR response. A remote authenticated attacker could use this
issue to consume resources, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-6170)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Too long query name causes segmentation fault in lwresd
vendor_redhat·2016-07-18·CVSS 5.9
CVE-2016-2775 [MEDIUM] CWE-20 bind: Too long query name causes segmentation fault in lwresd
bind: Too long query name causes segmentation fault in lwresd
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
It was found that the lightweight resolver protocol implementation in BIND could enter an infinite recursion and crash when asked to resolve a query name which, when combined with a search list entry, exceeds the maximum allowable length. A remote attacker could use this flaw to crash lwresd or named when using the "lwres" statement in named.conf.
Package: bind (Red Hat Enterprise Linux 5) - Will not fix
Package: bind97 (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-2775: bind9 - ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b...
vendor_debian·2016·CVSS 5.9
CVE-2016-2775 [MEDIUM] CVE-2016-2775: bind9 - ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b...
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-11)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-11)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-11)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-11)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2775 bind: Too long query name causes segmentation fault in lwresd
bugzilla·2016-07-19·CVSS 5.9
CVE-2016-2775 [MEDIUM] CVE-2016-2775 bind: Too long query name causes segmentation fault in lwresd
CVE-2016-2775 bind: Too long query name causes segmentation fault in lwresd
It was found that if the lightweight resolver is asked to resolve a query name which, when combined with a search list entry, exceeds the maximum allowable length, the server can terminate due to an error. If configured to use lwres lightweight resolver protocol accepting remote client connections, remote attacker can cause DoS by submitting large query.
External Reference:
https://kb.isc.org/article/AA-01393/
Discussion:
Created bind tracking bugs for this issue:
Affects: fedora-all [bug 1357804]
---
Created bind99 tracking bugs for this issue:
Affects: fedora-all [bug 1357805]
---
bind99-9.9.9-1.P2.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of i
Bugzilla
CVE-2016-2775 bind99: bind: Too long query name causes segmentation fault in lwresd [fedora-all]
bugzilla·2016-07-19·CVSS 5.9
CVE-2016-2775 [MEDIUM] CVE-2016-2775 bind99: bind: Too long query name causes segmentation fault in lwresd [fedora-all]
CVE-2016-2775 bind99: bind: Too long query name causes segmentation fault in lwresd [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2016-2775 bind: Too long query name causes segmentation fault in lwresd [fedora-all]
bugzilla·2016-07-19·CVSS 5.9
CVE-2016-2775 [MEDIUM] CVE-2016-2775 bind: Too long query name causes segmentation fault in lwresd [fedora-all]
CVE-2016-2775 bind: Too long query name causes segmentation fault in lwresd [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
http://www.securityfocus.com/bid/92037http://www.securitytracker.com/id/1036360https://access.redhat.com/errata/RHBA-2017:0651https://access.redhat.com/errata/RHBA-2017:1767https://access.redhat.com/errata/RHSA-2017:2533https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107https://kb.isc.org/article/AA-01393/74/CVE-2016-2775https://kb.isc.org/article/AA-01435https://kb.isc.org/article/AA-01436https://kb.isc.org/article/AA-01438https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7T2WJP5ELO4ZRSBXSETIZ3GAO6KOEFTA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZUCSMEOZIZ2R2SKA4FPLTOVZHJBAOWC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ5STNEUHBNEPUHJT7CYEVSMATFYMIX7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT754KDUJTKOASJODJX7FKHCOQ6EC7UX/https://security.gentoo.org/glsa/201610-07https://security.netapp.com/advisory/ntap-20160722-0002/http://www.securityfocus.com/bid/92037http://www.securitytracker.com/id/1036360https://access.redhat.com/errata/RHBA-2017:0651https://access.redhat.com/errata/RHBA-2017:1767https://access.redhat.com/errata/RHSA-2017:2533https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107https://kb.isc.org/article/AA-01393/74/CVE-2016-2775https://kb.isc.org/article/AA-01435https://kb.isc.org/article/AA-01436https://kb.isc.org/article/AA-01438https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7T2WJP5ELO4ZRSBXSETIZ3GAO6KOEFTA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZUCSMEOZIZ2R2SKA4FPLTOVZHJBAOWC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ5STNEUHBNEPUHJT7CYEVSMATFYMIX7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT754KDUJTKOASJODJX7FKHCOQ6EC7UX/https://security.gentoo.org/glsa/201610-07https://security.netapp.com/advisory/ntap-20160722-0002/
2016-07-19
Published