Vulnerability Description
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Isc | Bind | <= 9.9.7 |
Related Weaknesses (CWE)
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.htm
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.htm
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.htm
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html
- http://marc.info/?l=bugtraq&m=144000632319155&w=2
- http://marc.info/?l=bugtraq&m=144017354030745&w=2
- http://marc.info/?l=bugtraq&m=144181171013996&w=2
- http://marc.info/?l=bugtraq&m=144294073801304&w=2
FAQ
What is CVE-2015-5477?
CVE-2015-5477 is a vulnerability with a CVSS score of 7.8 (HIGH). named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
How severe is CVE-2015-5477?
CVE-2015-5477 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5477?
Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind.