Denial of service in ISC BIND - CVE-2016-2775
Published: July 19, 2016 / Updated: August 29, 2017
Vulnerability identifier: #VU164
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2775
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause the target service to crash.
The vulnerability exists due to boundary error in BIND. A remote unauthenticated attacker can cause the target BIND server to crash by sending a specially crafted request with a query name and a search list entry that exceeds the maximum allowable length.
Systems using the lightweight resolution protocol via either the 'lwresd' utility or via named using the "lwres" statement in 'named.conf' are affected.
Successful exploitation of this vulnerability may result in denial of service.
The vulnerability exists due to boundary error in BIND. A remote unauthenticated attacker can cause the target BIND server to crash by sending a specially crafted request with a query name and a search list entry that exceeds the maximum allowable length.
Systems using the lightweight resolution protocol via either the 'lwresd' utility or via named using the "lwres" statement in 'named.conf' are affected.
Successful exploitation of this vulnerability may result in denial of service.
Affected software
ISC BIND
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE Linux
Slackware Linux
Ubuntu
Fedora
Opensuse
bind (Alpine package)
bind9 (Ubuntu package)
lwresd (Ubuntu package)
dhcp
bind (Red Hat package) main
bind99
bind
Dell EMC Unisphere Central
How to mitigate CVE-2016-2775
The vendor has issued a fix (9.9.9-P2, 9.10.4-P2).
bind (Alpine package) - update to 9.10.4_p2-r0
bind9 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
lwresd (Ubuntu package) - update to Ubuntu Pro (Infra-only)
Dell EMC Unisphere Central - update to 4.0.7
dhcp - update to 4.3.3-10.P1.fc23
bind (Red Hat package) main - addressed in versions 9.8.2-0.62.rc1.el6, 9.9.4-50.el7
bind99 - addressed in versions 9.9.9-1.P2.fc23, 9.9.9-1.P2.fc24
bind - addressed in versions 9.10.4-1.P2.fc23, 9.10.4-1.P2.fc24
bind9 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
lwresd (Ubuntu package) - update to Ubuntu Pro (Infra-only)
Dell EMC Unisphere Central - update to 4.0.7
dhcp - update to 4.3.3-10.P1.fc23
bind (Red Hat package) main - addressed in versions 9.8.2-0.62.rc1.el6, 9.9.4-50.el7
bind99 - addressed in versions 9.9.9-1.P2.fc23, 9.9.9-1.P2.fc24
bind - addressed in versions 9.10.4-1.P2.fc23, 9.10.4-1.P2.fc24
External References
Related Security Bulletins
- Red Hat update for ISC BIND
- Arch Linux update for bind
- Slackware Linux update for bind
- Amazon Linux AMI update for bind
- OpenSUSE Linux update for bind
- SUSE Linux update for bind
- SUSE Linux update for bind
- Denial of service in bind (Alpine package)
- Multiple vulnerabilities in Dell EMC Unisphere Central
- Ubuntu update for bind9
- Fedora 24 update for bind
- Fedora 23 update for bind99, dhcp
- Fedora 24 update for bind99
- Fedora 23 update for bind
- Red Hat Enterprise Linux 6 update for bind
- Red Hat Enterprise Linux 7 update for bind