#VU67546 Out-of-bounds read in ISC BIND - CVE-2022-2881
Published: September 21, 2022 / Updated: October 20, 2022
ISC BIND
ISC
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when reusing HTTP connection while requesting statistics from the stats channel. A remote DNS server under attacker's control trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.