5
CVSSv2

CVE-2016-2848

Published: 21/10/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ISC BIND 9.1.0 up to and including 9.8.4-P2 and 9.9.0 up to and including 9.9.2-P2 allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.6.2

isc bind 9.9.2

isc bind 9.8.3

isc bind 9.6.1

isc bind 9.2.0

isc bind 9.1.1

isc bind 9.8.4

isc bind 9.3.1

isc bind 9.8.1

isc bind 9.5.0

isc bind 9.4.3

isc bind 9.5.2

isc bind 9.2.3

isc bind 9.7.5

isc bind 9.1.3

isc bind 9.5.1

isc bind 9.7.0

isc bind 9.9.0

isc bind 9.6

isc bind 9.7.1

isc bind 9.7.2

isc bind 9.4.0

isc bind 9.3.5

isc bind 9.8.2

isc bind 9.3.2

isc bind 9.7.4

isc bind 9.2.8

isc bind 9.2

isc bind 9.3.0

isc bind 9.2.4

isc bind 9.2.1

isc bind 9.5

isc bind 9.3

isc bind 9.7.7

isc bind 9.3.4

isc bind 9.1.0

isc bind 9.8.0

isc bind 9.2.7

isc bind 9.2.5

isc bind 9.7.6

isc bind 9.6.3

isc bind 9.3.6

isc bind 9.2.2

isc bind 9.4.1

isc bind 9.3.3

isc bind 9.9.1

isc bind 9.6.0

isc bind 9.4

isc bind 9.1.2

isc bind 9.4.2

isc bind 9.7.3

isc bind 9.1

isc bind 9.2.9

isc bind 9.5.3

isc bind 9.2.6

Vendor Advisories

Bind could be made to crash if it received specially crafted network traffic ...
Debian Bug report logs - #839051 bind9: CVE-2016-2848: A packet with malformed options can trigger an assertion failure Package: bind9; Maintainer for bind9 is Debian DNS Team <team+dns@trackerdebianorg>; Source for bind9 is src:bind9 (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Wed, 2 ...
Synopsis Important: bind97 security update Type/Severity Security Advisory: Important Topic An update for bind97 is now available for Red Hat Enterprise Linux 5Red Hat Product Security has rated this update as having a security impact ofImportant A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: bind security update Type/Severity Security Advisory: Important Topic An update for bind is now available for Red Hat Enterprise Linux 5 and Red HatEnterprise Linux 6Red Hat Product Security has rated this update as having a security impact ofImportant A Common Vulnerability Scoring Sy ...
Synopsis Important: bind security update Type/Severity Security Advisory: Important Topic An update for bind is now available for Red Hat Enterprise Linux 62 Advanced Update Support, Red Hat Enterprise Linux 64 Advanced Update Support, Red Hat Enterprise Linux 65 Advanced Update Support, Red Hat Enterpri ...
CVE-2016-2848 bind: assertion failure triggered by a packet with malformed options A denial of service flaw was found in the way BIND handled packets with malformed options A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS packet ...
A denial of service flaw was found in the way BIND handled packets with malformed options A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS packet ...