Denial of service in ISC products - CVE-2016-2848

 

Denial of service in ISC products - CVE-2016-2848

Published: October 20, 2016 / Updated: January 11, 2017


Vulnerability identifier: #VU1043
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2848
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to perform DoS attack on the targete system.
The weakness is due to insuffcient handling of  options data in an OPT resource record. By sending a specially crafted DNS packet, attackers can trigger the named service to crash.
Successful exploitation of the vulnerability leads to denial of service on the vulnarable system.

Affected software

Oracle VM Server for x86
Oracle Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Ubuntu
openEuler
ISC BIND
xorg-x11-server-Xwayland
xorg-x11-server-Xwayland-debuginfo
xorg-x11-server-Xwayland-debugsource
xorg-x11-server-Xwayland-devel

How to mitigate CVE-2016-2848

Update to version 9.9.9-P3, 9.10.4-P3 or 9.11.0.

xorg-x11-server-Xwayland - update to 22.1.2-6
xorg-x11-server-Xwayland-debuginfo - update to 22.1.2-6
xorg-x11-server-Xwayland-debugsource - update to 22.1.2-6
xorg-x11-server-Xwayland-devel - update to 22.1.2-6

External References

Related Security Bulletins