CVE-2016-2776
ISC BIND 9 - Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
buffer.c en named en ISC BIND 9 en versiones anteriores a 9.9.9-P3, 9.10.x en versiones anteriores a 9.10.4-P3 y 9.11.x en versiones anteriores a 9.11.0rc3 no construye respuestas adecuadamente, lo que permite a atacantes remotos provocar una denegación de servicio (fallo de aserción y salida de demonio) a través de una consulta manipulada.
A denial of service flaw was found in the way BIND constructed a response to a query that met certain criteria. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS request packet.
A defect in the rendering of messages into packets can cause named to exit with an assertion failure in buffer.c while constructing a response to a query that meets certain criteria. This assertion can be triggered even if the apparent source address isnt allowed to make queries.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-02-26 CVE Reserved
- 2016-09-28 CVE Published
- 2016-10-03 First Exploit
- 2024-08-05 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-617: Reachable Assertion
CAPEC
References (21)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html | Third Party Advisory | |
http://www.securityfocus.com/bid/93188 | Vdb Entry | |
http://www.securitytracker.com/id/1036903 | Vdb Entry | |
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107 | Third Party Advisory | |
https://kb.isc.org/article/AA-01435 | X_refsource_confirm | |
https://kb.isc.org/article/AA-01436 | X_refsource_confirm | |
https://kb.isc.org/article/AA-01438 | X_refsource_confirm | |
https://security.netapp.com/advisory/ntap-20160930-0001 | X_refsource_confirm | |
http://blog.infobytesec.com/2016/10/a-tale-of-dns-packet-cve-2016-2776.html |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/40453 | 2024-08-05 | |
https://github.com/infobyte/CVE-2016-2776 | 2016-10-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2016-1944.html | 2019-12-27 | |
http://rhn.redhat.com/errata/RHSA-2016-1945.html | 2019-12-27 | |
http://rhn.redhat.com/errata/RHSA-2016-2099.html | 2019-12-27 | |
https://kb.isc.org/article/AA-01419/0 | 2019-12-27 | |
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:28.bind.asc | 2019-12-27 | |
https://security.gentoo.org/glsa/201610-07 | 2019-12-27 | |
https://access.redhat.com/security/cve/CVE-2016-2776 | 2016-10-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1378380 | 2016-10-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | 5.0 Search vendor "Oracle" for product "Linux" and version "5.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | 6 Search vendor "Oracle" for product "Linux" and version "6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | 7 Search vendor "Oracle" for product "Linux" and version "7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Server Search vendor "Oracle" for product "Vm Server" | 3.2 Search vendor "Oracle" for product "Vm Server" and version "3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Server Search vendor "Oracle" for product "Vm Server" | 3.3 Search vendor "Oracle" for product "Vm Server" and version "3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Vm Server Search vendor "Oracle" for product "Vm Server" | 3.4 Search vendor "Oracle" for product "Vm Server" and version "3.4" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | <= 9.9.9 Search vendor "Isc" for product "Bind" and version " <= 9.9.9" | p3 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | a1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | a2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | b2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | p2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.0 Search vendor "Isc" for product "Bind" and version "9.10.0" | rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | b2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | p2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.1 Search vendor "Isc" for product "Bind" and version "9.10.1" | rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | p2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | p3 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | p4 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.2 Search vendor "Isc" for product "Bind" and version "9.10.2" | rc2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | p1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | p2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | p3 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | p4 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.3 Search vendor "Isc" for product "Bind" and version "9.10.3" | rc1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.4 Search vendor "Isc" for product "Bind" and version "9.10.4" | p2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.10.4 Search vendor "Isc" for product "Bind" and version "9.10.4" | p3 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | a1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | a2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | a3 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | b1 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | b2 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | b3 |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.11.0 Search vendor "Isc" for product "Bind" and version "9.11.0" | rc1 |
Affected
| ||||||
Hp Search vendor "Hp" | Hp-ux Search vendor "Hp" for product "Hp-ux" | 11.31 Search vendor "Hp" for product "Hp-ux" and version "11.31" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 10.0 Search vendor "Oracle" for product "Solaris" and version "10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 11.3 Search vendor "Oracle" for product "Solaris" and version "11.3" | - |
Affected
|