Resource management error in ISC BIND - CVE-2015-1349

 

Resource management error in ISC BIND - CVE-2015-1349

Published: February 19, 2015 / Updated: July 24, 2020


Vulnerability identifier: #VU31833
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1349
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.


Affected software

ISC BIND
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Fedora
bind (Alpine package)
bind

How to mitigate CVE-2015-1349

Install update from vendor's website.

bind (Alpine package) - update to 9.9.6_p2-r0
bind - update to 9.9.6-8.P1.fc21

External References

Related Security Bulletins