Vulnerability Description
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Linux | 5.0 |
| Oracle | Vm Server | 3.2 |
| Isc | Bind | <= 9.9.9 |
| Hp | Hp-Ux | 11.31 |
| Oracle | Solaris | 10.0 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2016-1944.html
- http://rhn.redhat.com/errata/RHSA-2016-1945.html
- http://rhn.redhat.com/errata/RHSA-2016-2099.html
- http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.hThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmThird Party Advisory
- http://www.securityfocus.com/bid/93188
- http://www.securitytracker.com/id/1036903
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cThird Party Advisory
- https://kb.isc.org/article/AA-01419/0Vendor Advisory
- https://kb.isc.org/article/AA-01435
- https://kb.isc.org/article/AA-01436
- https://kb.isc.org/article/AA-01438
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:28.bind.asc
- https://security.gentoo.org/glsa/201610-07
FAQ
What is CVE-2016-2776?
CVE-2016-2776 is a vulnerability with a CVSS score of 7.5 (HIGH). buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service ...
How severe is CVE-2016-2776?
CVE-2016-2776 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2776?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Linux, Oracle Vm Server, Isc Bind, Hp Hp-Ux, Oracle Solaris.