Denial of service in ISC BIND - CVE-2016-2775

 

Denial of service in ISC BIND - CVE-2016-2775

Published: July 19, 2016 / Updated: August 29, 2017


Vulnerability identifier: #VU164
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2775
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause the target service to crash.

The vulnerability exists due to boundary error in BIND. A remote unauthenticated attacker can cause the target BIND server to crash by sending a specially crafted request with a query name and a search list entry that exceeds the maximum allowable length.

Systems using the lightweight resolution protocol via either the 'lwresd' utility or via named using the "lwres" statement in 'named.conf' are affected.

Successful exploitation of this vulnerability may result in denial of service.


Affected software


ISC BIND
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE Linux
Slackware Linux
Ubuntu
Fedora
Opensuse
bind (Alpine package)
bind9 (Ubuntu package)
lwresd (Ubuntu package)
dhcp
bind (Red Hat package) main
bind99
bind
Dell EMC Unisphere Central

How to mitigate CVE-2016-2775

The vendor has issued a fix (9.9.9-P2, 9.10.4-P2).

bind (Alpine package) - update to 9.10.4_p2-r0
bind9 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
lwresd (Ubuntu package) - update to Ubuntu Pro (Infra-only)
Dell EMC Unisphere Central - update to 4.0.7
dhcp - update to 4.3.3-10.P1.fc23
bind (Red Hat package) main - addressed in versions 9.8.2-0.62.rc1.el6, 9.9.4-50.el7
bind99 - addressed in versions 9.9.9-1.P2.fc23, 9.9.9-1.P2.fc24
bind - addressed in versions 9.10.4-1.P2.fc23, 9.10.4-1.P2.fc24

External References

Related Security Bulletins