Data Handling in ISC BIND - CVE-2015-5477
Published: July 29, 2015 / Updated: July 27, 2020
Vulnerability identifier: #VU31954
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5477
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
Affected software
ISC BIND
Gentoo Linux
Amazon Linux AMI
SUSE Linux
Slackware Linux
Fedora
bind (Alpine package)
bind
bind99
Gentoo Linux
Amazon Linux AMI
SUSE Linux
Slackware Linux
Fedora
bind (Alpine package)
bind
bind99
How to mitigate CVE-2015-5477
Install update from vendor's website.
bind (Alpine package) - update to 9.9.7_p2-r0
bind - addressed in versions 9.9.6-10.P1.fc21, 9.10.2-4.P3.fc22
bind99 - update to 9.9.7-6.P2.fc22
bind - addressed in versions 9.9.6-10.P1.fc21, 9.10.2-4.P3.fc22
bind99 - update to 9.9.7-6.P2.fc22
External References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html
- http://marc.info/?l=bugtraq&m=144000632319155&w=2
- http://marc.info/?l=bugtraq&m=144017354030745&w=2
- http://marc.info/?l=bugtraq&m=144181171013996&w=2
- http://marc.info/?l=bugtraq&m=144294073801304&w=2
- http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html
- http://rhn.redhat.com/errata/RHSA-2015-1513.html
- http://rhn.redhat.com/errata/RHSA-2015-1514.html
- http://rhn.redhat.com/errata/RHSA-2015-1515.html
- http://rhn.redhat.com/errata/RHSA-2016-0078.html
- http://rhn.redhat.com/errata/RHSA-2016-0079.html
- http://www.debian.org/security/2015/dsa-3319
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/76092
- http://www.securitytracker.com/id/1033100
- http://www.ubuntu.com/usn/USN-2693-1
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918
- https://kb.isc.org/article/AA-01272
- https://kb.isc.org/article/AA-01305
- https://kb.isc.org/article/AA-01306
- https://kb.isc.org/article/AA-01307
- https://kb.isc.org/article/AA-01438
- https://kb.juniper.net/JSA10783
- https://kc.mcafee.com/corporate/index?page=content&id=SB10126
- https://security.gentoo.org/glsa/201510-01
- https://security.netapp.com/advisory/ntap-20160114-0001/
- https://support.apple.com/kb/HT205032
- https://www.exploit-db.com/exploits/37721/
- https://www.exploit-db.com/exploits/37723/
Related Security Bulletins
- Data Handling in ISC BIND
- SUSE Linux update for bind
- SUSE Linux update for bind
- SUSE Linux update for bind
- SUSE Linux update for bind
- SUSE Linux update for bind
- Data Handling in bind (Alpine package)
- Amazon Linux AMI update for bind
- Gentoo update for BIND
- Slackware Linux update for bind
- Fedora 22 update for bind99
- Fedora 22 update for bind
- Fedora 21 update for bind