Race condition in ISC BIND - CVE-2015-8461
Published: December 16, 2015 / Updated: July 24, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
Affected software
Amazon Linux AMI
Slackware Linux
Fedora
bind (Alpine package)
dnsperf
bind-dyndb-ldap
bind
How to mitigate CVE-2015-8461
dnsperf - addressed in versions 2.0.0.0-19.fc22, 2.0.0.0-19.fc23
bind-dyndb-ldap - addressed in versions 7.0-6.fc22, 8.0-4.fc23
bind - addressed in versions 9.10.3-7.P2.fc22, 9.10.3-7.P2.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174145.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174252.html
- http://www.securityfocus.com/bid/79347
- http://www.securitytracker.com/id/1034419
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966
- https://kb.isc.org/article/AA-01319
- https://kb.isc.org/article/AA-01380
- https://kb.isc.org/article/AA-01438