Input validation error in ISC BIND - CVE-2015-8704

 

Input validation error in ISC BIND - CVE-2015-8704

Published: January 20, 2016 / Updated: July 27, 2020


Vulnerability identifier: #VU31952
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8704
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.

apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.


Affected software

ISC BIND
Amazon Linux AMI
SUSE Linux
Slackware Linux
Fedora
Opensuse
bind (Alpine package)
bind99
bind
Dell EMC Unisphere Central

How to mitigate CVE-2015-8704

Install update from vendor's website.

bind (Alpine package) - update to 9.10.3_p3-r0
Dell EMC Unisphere Central - update to 4.0.7
bind99 - addressed in versions 9.9.8-2.P3.fc22, 9.9.8-2.P3.fc23
bind - addressed in versions 9.10.3-8.P3.fc22, 9.10.3-10.P3.fc23

External References

Related Security Bulletins