Denial of service - CVE-2016-6876

 

Denial of service - CVE-2016-6876

Published: September 8, 2016 / Updated: September 9, 2016


Vulnerability identifier: #VU384
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-6876
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

A remote user can cause excessive resources spending and bring the service to crash.

A remote user can return a specially crafted reply to DNS request from 'RESOLV::lookup'  and cause excessive resource consumption or possible Traffic Management Microkernel (TMM) crash.

Successful exploitation of this vulnerability will allow an attacker to cause a denial of service, however requires that the system uses the 'RESOLV::lookup' iRule command to resolve PTR records.


How to mitigate CVE-2016-6876



Sources