Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.810976
Categoría:Denial of Service
Título:ISC BIND DNS64 Denial of Service Vulnerability - Linux
Resumen:ISC BIND is prone to a denial of service vulnerability.
Descripción:Summary:
ISC BIND is prone to a denial of service vulnerability.

Vulnerability Insight:
The flaw exists due to improper
handling of queries when server is configured to use DNS64 and if the
option 'break-dnssec yes' is in use.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to cause a denial-of-service of a server.

Affected Software/OS:
ISC BIND 9.8.0 through 9.8.8-P1, 9.9.0
through 9.9.9-P6, 9.9.10b1 through 9.9.10rc1, 9.10.0 through 9.10.4-P6,
9.10.5b1 through 9.10.5rc1, 9.11.0 through 9.11.0-P3, 9.11.1b1 through
9.11.1rc1, 9.9.3-S1 through 9.9.9-S8.

Solution:
Update to ISC BIND version 9.9.9-P8
or 9.9.10rc3 or 9.10.5rc3 or 9.11.1rc3 or 9.9.9-S10 or 9.10.4-P8 or
9.11.0-P5 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Referencia Cruzada: BugTraq ID: 97653
Common Vulnerability Exposure (CVE) ID: CVE-2017-3136
http://www.securityfocus.com/bid/97653
Debian Security Information: DSA-3854 (Google Search)
https://www.debian.org/security/2017/dsa-3854
https://security.gentoo.org/glsa/201708-01
RedHat Security Advisories: RHSA-2017:1095
https://access.redhat.com/errata/RHSA-2017:1095
RedHat Security Advisories: RHSA-2017:1105
https://access.redhat.com/errata/RHSA-2017:1105
http://www.securitytracker.com/id/1038259
SuSE Security Announcement: openSUSE-SU-2020:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
SuSE Security Announcement: openSUSE-SU-2020:1701 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.