ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND 9.16.33之前版本、9.18.7之前的9.18.x版本、9.19.5之前的9.19.x版本存在安全漏洞,该漏洞源于解析器代码中的缺陷可能会导致命名在处理大型委托上花费过多的时间,攻击者通过利用此漏洞向目标解析器充斥查询,可以显着削弱解析器的性能,从而有效地拒绝合法客户端访问DNS解析服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-3080 | 7.5 HIGH | BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeo |
| CVE-2022-38178 | 7.5 HIGH | Memory leaks in EdDSA DNSSEC verification code |
| CVE-2022-38177 | 7.5 HIGH | Memory leak in ECDSA DNSSEC verification code |
| CVE-2022-2906 | 7.5 HIGH | Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ onl |
| CVE-2022-2881 | 5.5 MEDIUM | Buffer overread in statistics channel code |
No comments yet