ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND中存在输入验证错误漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。以下产品及版本受到影响:ISC BIND 9.7.0版本至9.8.8版本,9.9.0版本至9.9.13版本,9.10.0版本至9.10.8版本,9.11.0版本至9.11.4版本,9.12.0版本至9.12.2版本,9.13.0版本至9.13.2版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/sischkg/cve-2018-5740 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-3143 | An error in TSIG authentication can permit unauthorized dynamic updates | |
| CVE-2018-5741 | Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their | |
| CVE-2018-5739 | Failure to release memory may exhaust system resources | |
| CVE-2018-5738 | Some versions of BIND can improperly permit recursive query service to unauthorized client | |
| CVE-2018-5737 | BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other | |
| CVE-2018-5734 | A malformed request can trigger an assertion failure in badcache.c | |
| CVE-2018-5733 | A malicious client can overflow a reference counter in ISC dhcpd | |
| CVE-2017-3145 | Improper fetch cleanup sequencing in the resolver can cause named to crash | |
| CVE-2017-3144 | Failure to properly clean up closed OMAPI connections can exhaust available sockets | |
| CVE-2016-9778 | An error handling certain queries using the nxdomain-redirect feature could cause a REQUIR | |
| CVE-2017-3142 | An error in TSIG authentication can permit unauthorized zone transfers | |
| CVE-2017-3141 | Windows service and uninstall paths are not quoted when BIND is installed | |
| CVE-2017-3140 | An error processing RPZ rules can cause named to loop endlessly after handling a query | |
| CVE-2017-3138 | named exits with a REQUIRE assertion failure if it receives a null command string on its c | |
| CVE-2017-3137 | A response packet can cause a resolver to terminate when processing an answer containing a | |
| CVE-2017-3136 | An error handling synthesized records could cause an assertion failure when using DNS64 wi | |
| CVE-2017-3135 | Combination of DNS64 and RPZ Can Lead to Crash |
No comments yet