cbcvebase.
CVE-2016-2848
published 2016-10-21

CVE-2016-2848: ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via…

PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
25.77%
97.7th percentile
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.9.3.dfsg.P2-1 (bookworm)bind9 1:9.9.3.dfsg.P2-1 (bookworm)
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: BIND named process crashes with an assertion failure upon receiving a DNS packet containing a malformed OPT resource record options section. Both authoritative and recursive server configurations are vulnerable.
  • Detection focus: monitor for unexpected named (BIND) process termination accompanied by assertion failure messages in logs, triggered by inbound DNS packets with malformed OPT RR options data.
  • Patch reference: the fix is BIND change #3548, corresponding to upstream commit 4adf97c32fcca7d00e5756607fd045f2aab9c3d4. Systems not containing this change are vulnerable.
  • ·Affected BIND versions are 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2; both authoritative and recursive server roles are vulnerable.
  • ·Red Hat Enterprise Linux 7 is listed as Not Affected; RHEL 4 is Will Not Fix. Debian resolved the issue in package version 1:9.9.3.dfsg.P2-1.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.