#VU32396 Input validation error in ISC BIND - CVE-2015-5986
Published: September 5, 2015 / Updated: July 28, 2020
ISC BIND
ISC
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
Remediation
External links
- http://lists.apple.com/archives/security-announce/2015/Oct/msg00009.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165810.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167465.html
- http://www.securityfocus.com/bid/76618
- http://www.securitytracker.com/id/1033453
- https://kb.isc.org/article/AA-01291
- https://kb.isc.org/article/AA-01305
- https://kb.isc.org/article/AA-01306
- https://kb.isc.org/article/AA-01307
- https://kb.isc.org/article/AA-01438
- https://kc.mcafee.com/corporate/index?page=content&id=SB10134
- https://security.gentoo.org/glsa/201510-01
- https://security.netapp.com/advisory/ntap-20190730-0001/
- https://support.apple.com/HT205376