ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 BIND存在安全漏洞,该漏洞源于使用格式错误的EdDSA签名,欺骗目标解析程序,导致内存因资源不足而崩溃。以下产品及版本受到影响:9.9.12版本至9.9.13版本、9.10.7版本至9.10.8版本、9.11.3版本至9.16.32版本、9.18.0版本至 9.18.6版本、9.19.0版本至9.19.4版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-3080 | 7.5 HIGH | BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeo |
| CVE-2022-38177 | 7.5 HIGH | Memory leak in ECDSA DNSSEC verification code |
| CVE-2022-2906 | 7.5 HIGH | Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ onl |
| CVE-2022-2881 | 5.5 MEDIUM | Buffer overread in statistics channel code |
| CVE-2022-2795 | 5.3 MEDIUM | Processing large delegations may severely degrade resolver performance |
No comments yet