ISC BIND是美国Internet Systems Consortium(ISC)公司所维护的一套实现了DNS协议的开源软件。 ISC BIND中存在远程拒绝服务漏洞。远程攻击者可通过发送请求利用该漏洞造成拒绝服务。以下版本受到影响:ISC BIND 9.9.9版本至9.9.9-P7版本,9.9.10b1版本至9.9.10rc2版本,9.10.4版本至9.10.4-P7版本,9.10.5b1版本至9.10.5rc2版本,9.11.0版本至9.11.0-P4版本,9.11.1b1版本至9.11.1rc2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-3144 | Failure to properly clean up closed OMAPI connections can exhaust available sockets | |
| CVE-2018-5741 | Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their | |
| CVE-2018-5740 | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named | |
| CVE-2018-5739 | Failure to release memory may exhaust system resources | |
| CVE-2018-5738 | Some versions of BIND can improperly permit recursive query service to unauthorized client | |
| CVE-2018-5737 | BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other | |
| CVE-2018-5734 | A malformed request can trigger an assertion failure in badcache.c | |
| CVE-2018-5733 | A malicious client can overflow a reference counter in ISC dhcpd | |
| CVE-2017-3145 | Improper fetch cleanup sequencing in the resolver can cause named to crash | |
| CVE-2016-9778 | An error handling certain queries using the nxdomain-redirect feature could cause a REQUIR | |
| CVE-2017-3143 | An error in TSIG authentication can permit unauthorized dynamic updates | |
| CVE-2017-3142 | An error in TSIG authentication can permit unauthorized zone transfers | |
| CVE-2017-3141 | Windows service and uninstall paths are not quoted when BIND is installed | |
| CVE-2017-3140 | An error processing RPZ rules can cause named to loop endlessly after handling a query | |
| CVE-2017-3137 | A response packet can cause a resolver to terminate when processing an answer containing a | |
| CVE-2017-3136 | An error handling synthesized records could cause an assertion failure when using DNS64 wi | |
| CVE-2017-3135 | Combination of DNS64 and RPZ Can Lead to Crash |
No comments yet