CVE-2016-9444
published 2017-01-12CVE-2016-9444: named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion…
PriorityP348high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
18.12%
96.9th percentile
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-11 (bookworm) | bind9 1:9.10.3.dfsg.P4-11 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9131)
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9147)
It was discovered that Bind incorrectly handled certain malformed DS record
responses. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444
Red Hat
bind: assertion failure while handling an unusually-formed DS record response
vendor_redhat·2017-01-11·CVSS 7.5
CVE-2016-9444 [HIGH] bind: assertion failure while handling an unusually-formed DS record response
bind: assertion failure while handling an unusually-formed DS record response
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
A denial of service flaw was found in the way BIND handled an unusually-formed DS record response. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-9444: bind9 - named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x befor...
vendor_debian·2016·CVSS 7.5
CVE-2016-9444 [HIGH] CVE-2016-9444: bind9 - named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x befor...
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-11)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-11)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-11)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-11)
GHSA
GHSA-gpxq-r8wx-qxgw: named in ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2016-9444 [HIGH] CWE-20 GHSA-gpxq-r8wx-qxgw: named in ISC BIND 9
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
OSV
bind9 vulnerabilities
osv·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9131)
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9147)
It was discovered that Bind incorrectly handled certain malformed DS record
responses. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444)
OSV
CVE-2016-9444: named in ISC BIND 9
osv·2017-01-12·CVSS 7.5
CVE-2016-9444 [HIGH] CVE-2016-9444: named in ISC BIND 9
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9444 bind99: bind: assertion failure while handling an unusually-formed DS record response [fedora-all]
bugzilla·2017-01-12·CVSS 7.5
CVE-2016-9444 [HIGH] CVE-2016-9444 bind99: bind: assertion failure while handling an unusually-formed DS record response [fedora-all]
CVE-2016-9444 bind99: bind: assertion failure while handling an unusually-formed DS record response [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response [fedora-all]
bugzilla·2017-01-12·CVSS 7.5
CVE-2016-9444 [HIGH] CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response [fedora-all]
CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response
bugzilla·2017-01-09·CVSS 7.5
CVE-2016-9444 [HIGH] CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response
CVE-2016-9444 bind: assertion failure while handling an unusually-formed DS record response
An unusually-formed answer containing a DS resource record could trigger an assertion failure. While the combination of properties which triggers the assertion should not occur in normal traffic, it is potentially possible for the assertion to be triggered deliberately by an attacker sending a specially-constructed answer having the required properties.
This vulnerability occurs during the processing of an answer packet received in response to a query. As a result, recursive servers are at the greatest risk; authoritative servers are at risk only to the extent that they perform a limited set of queries.
This description is borrowed from the upstream advisory.
Discussion:
Acknowledgments:
Name:
Fortinet
The Analysis of ISC BIND Response Authority Section RRSIG Missing DoS (CVE-2016-9444)
blogs_fortinet·2017-02-06·CVSS 7.5
CVE-2016-9444 [HIGH] The Analysis of ISC BIND Response Authority Section RRSIG Missing DoS (CVE-2016-9444)
FORTIGUARD LABS THREAT RESEARCH
The Analysis of ISC BIND Response Authority Section RRSIG Missing DoS (CVE-2016-9444)
By Dehui Yin | February 06, 2017
Domain Name System Security Extensions (DNSSEC) secures the Domain Name System (DNS), right?
Yes, but that’s not the whole story. DNSSEC can also introduce troubles into your DNS server.
Recently, a BIND bug caused by a missing RRSIG record, which is a part of DNSSEC, was fixed by a patch from the Internet Systems Consortium (ISC). This bug affects all versions of BIND recursive servers, and can cause a denial of service (DoS.)
This potential DoS vulnerability is caused by a RUNTIME CHECK error in Resolver.c when handling the DNS query response AUTHORITY section without covering RRSIG. In this post we will examine the BIND source codes
http://rhn.redhat.com/errata/RHSA-2017-0062.htmlhttp://www.debian.org/security/2017/dsa-3758http://www.securityfocus.com/bid/95393http://www.securitytracker.com/id/1037582https://access.redhat.com/errata/RHSA-2017:1583https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05381687https://kb.isc.org/article/AA-01441/74/CVE-2016-9444https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/http://rhn.redhat.com/errata/RHSA-2017-0062.htmlhttp://www.debian.org/security/2017/dsa-3758http://www.securityfocus.com/bid/95393http://www.securitytracker.com/id/1037582https://access.redhat.com/errata/RHSA-2017:1583https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05381687https://kb.isc.org/article/AA-01441/74/CVE-2016-9444https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/
2017-01-12
Published