Vulnerabilities
Vulnerable Software
Isc:  >> Bind  >> 9.18.2  Security Vulnerabilities
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
CVSS Score
5.3
EPSS Score
0.003
Published
2022-09-21
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
CVSS Score
5.5
EPSS Score
0.004
Published
2022-09-21
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-09-21
By sending specific queries to the resolver, an attacker can cause named to crash.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-09-21
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-05-19


Contact Us

Shodan ® - All rights reserved