CVE-2016-2776

UnknownEPSS 89.48%

Last modified

CVE-2016-2776 is a vulnerability of currently unknown severity. buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.. EPSS estimates a 89.48% chance of exploitation in the next 30 days.

Description

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

Metrics

EPSS Probability
89.48%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
OracleLinux5.0
OracleLinux6
OracleLinux7
OracleVm Server3.2
OracleVm Server3.3
OracleVm Server3.4
IscBind<= 9.9.9P3
IscBind9.10.0
IscBind9.10.1
IscBind9.10.2B1
IscBind9.10.3
IscBind9.10.4P2
IscBind9.11.0A1
HpHp-Ux11.31
OracleSolaris10.0
OracleSolaris11.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-2776?
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
How severe is CVE-2016-2776?
Severity scoring for CVE-2016-2776 is pending analysis. The EPSS model estimates a 89.48% probability of exploitation in the next 30 days.
How do I fix CVE-2016-2776?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-2776?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST