CVE-2016-1284
Last modified
CVE-2016-1284 is a vulnerability of currently unknown severity. rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.. EPSS estimates a 3.31% chance of exploitation in the next 30 days.
Description
rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Isc | Bind | 9.9.8 | S1 |
References
- https://kb.isc.org/article/AA-01348Vendor Advisory
- https://kb.isc.org/article/AA-01438Release Notes
- https://kb.isc.org/article/AA-01348Vendor Advisory
- https://kb.isc.org/article/AA-01438Release Notes
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1284?
How severe is CVE-2016-1284?
How do I fix CVE-2016-1284?
Are you affected by CVE-2016-1284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
