// For flags

CVE-2015-5722

bind: malformed DNSSEC key failed assertion denial of service

Severity Score

7.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

Vulnerabilidad en buffer.c en nombrado en ISC BIND 9.x en versiones anteriores a 9.9.7-P3 y 9.10.x en versiones anteriores a 9.10.2-P4, permite a atacantes remotos causar una denegación de servicio (error de aserción y salida del demonio) mediante la creación de una zona de contención, una clave DNSSEC mal formada y la emisión de una consulta para un nombre en esa zona.

A denial of service flaw was found in the way BIND parsed certain malformed DNSSEC keys. A remote attacker could use this flaw to send a specially crafted DNS query (for example, a query requiring a response from a zone containing a deliberately malformed key) that would cause named functioning as a validating resolver to crash.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-08-03 CVE Reserved
  • 2015-09-02 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-11-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
  • CWE-617: Reachable Assertion
CAPEC
References (39)
URL Date SRC
URL Date SRC
URL Date SRC
http://lists.apple.com/archives/security-announce/2015/Oct/msg00009.html 2016-12-31
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168686.html 2016-12-31
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165750.html 2016-12-31
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165810.html 2016-12-31
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165996.html 2016-12-31
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167465.html 2016-12-31
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00005.html 2016-12-31
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00006.html 2016-12-31
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00012.html 2016-12-31
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00020.html 2016-12-31
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00002.html 2016-12-31
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html 2016-12-31
http://marc.info/?l=bugtraq&m=144294073801304&w=2 2016-12-31
http://rhn.redhat.com/errata/RHSA-2015-1705.html 2016-12-31
http://rhn.redhat.com/errata/RHSA-2015-1706.html 2016-12-31
http://rhn.redhat.com/errata/RHSA-2015-1707.html 2016-12-31
http://rhn.redhat.com/errata/RHSA-2016-0078.html 2016-12-31
http://rhn.redhat.com/errata/RHSA-2016-0079.html 2016-12-31
http://www.debian.org/security/2015/dsa-3350 2016-12-31
http://www.ubuntu.com/usn/USN-2728-1 2016-12-31
https://kb.isc.org/article/AA-01287 2016-12-31
https://security.gentoo.org/glsa/201510-01 2016-12-31
https://access.redhat.com/security/cve/CVE-2015-5722 2016-01-28
https://bugzilla.redhat.com/show_bug.cgi?id=1259087 2016-01-28
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
<= 9.9.7
Search vendor "Isc" for product "Bind" and version " <= 9.9.7"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
<= 9.10.2
Search vendor "Isc" for product "Bind" and version " <= 9.10.2"
p3
Affected
Apple
Search vendor "Apple"
Mac Os X Server
Search vendor "Apple" for product "Mac Os X Server"
5.0.15
Search vendor "Apple" for product "Mac Os X Server" and version "5.0.15"
-
Affected