383
VMScore

CVE-2022-1183

Published: 19/05/2022 Updated: 07/10/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.19.0

isc bind

netapp h410c_firmware -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h410s_firmware -

Vendor Advisories

An assertion failure can be triggered if a TLS connection to a configured http TLS listener with a defined endpoint is destroyed too early On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure Vulnerable configurations are those that include a reference to http within the listen-on stateme ...