cbcvebase.
CVE-2022-3080
published 2022-09-21

CVE-2022-3080: By sending specific queries to the resolver, an attacker can cause named to crash.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
By sending specific queries to the resolver, an attacker can cause named to crash.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.18.7-1 (bookworm)bind9 1:9.18.7-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
iscbind
iscbind
iscbind
iscbind>= 9.16.14 < 9.16.339.16.33
iscbind>= 9.18.0 < 9.18.79.18.7
iscbind>= 9.19.0 < 9.19.59.19.5
iscbind9
iscbind9
iscbind9
iscbind9
iscbind9>= 0 < 1:9.16.33-1~deb11u11:9.16.33-1~deb11u1
iscbind9>= 0 < 1:9.18.7-11:9.18.7-1
iscbind9>= 0 < 1:9.18.7-11:9.18.7-1
iscbind9>= 0 < 1:9.18.7-11:9.18.7-1
iscbind9>= 0 < 1:9.11.3+dfsg-1ubuntu1.181:9.11.3+dfsg-1ubuntu1.18
iscbind9>= 0 < 1:9.16.1-0ubuntu2.111:9.16.1-0ubuntu2.11
iscbind9>= 0 < 1:9.18.1-1ubuntu1.21:9.18.1-1ubuntu1.2
msrccbl2_bind_9.16.33-1_on_cbl_mariner_2.0
msrccm1_bind_9.16.33-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH