CVE-2022-0667

Severity
7.5HIGH
EPSS
0.7%
top 28.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 22
Latest updateMar 23

Description

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianbind9< 1:9.18.1-1+2
CVEListV5isc/bind9.18.0
NVDisc/bind9.18.0

🔴Vulnerability Details

3
GHSA
GHSA-mmmq-7jwv-j64j: When the vulnerability is triggered the BIND process will exit2022-03-23
CVEList
Assertion failure on delayed DS lookup2022-03-22
OSV
CVE-2022-0667: When the vulnerability is triggered the BIND process will exit2022-03-22

📋Vendor Advisories

2
Red Hat
bind: When chasing DS records, a timed-out or artificially delayed fetch could cause 'named' to crash while resuming a DS lookup2022-03-16
Debian
CVE-2022-0667: bind9 - When the vulnerability is triggered the BIND process will exit. BIND 9.18.02022
CVE-2022-0667 (HIGH CVSS 7.5) | When the vulnerability is triggered | cvebase.io