ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND 9.16.33之前版本、9.18.7之前的9.18.x版本、9.19.5之前的9.19.x版本存在安全漏洞,该漏洞源于当启用陈旧缓存和陈旧答案时,选项stale-answer-client-timeout设置为0,并且缓存中存在用于传入查询的陈旧CNAME时,解析器可能会崩溃。通过向解析器发送特定查询,攻击者可以导致命名崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-38178 | 7.5 HIGH | Memory leaks in EdDSA DNSSEC verification code |
| CVE-2022-38177 | 7.5 HIGH | Memory leak in ECDSA DNSSEC verification code |
| CVE-2022-2906 | 7.5 HIGH | Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ onl |
| CVE-2022-2881 | 5.5 MEDIUM | Buffer overread in statistics channel code |
| CVE-2022-2795 | 5.3 MEDIUM | Processing large delegations may severely degrade resolver performance |
No comments yet