CVE-2015-5477
KEV
🔴 Łataj teraz
Błąd w ISC BIND umożliwia zdalnym atakującym wywołanie awarii usługi.
CVSS
7.5
EPSS
91.3%
Exploit
weaponized
Vendor
isc
Opis źródłowy (NVD)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 91.3% |
| Opublikowano (NVD) | 2015-07-29 14:59:05 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 18:17:11 UTC |
Referencje
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718 ([email protected])
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html ([email protected])
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html ([email protected])
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html ([email protected])
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html ([email protected])
- http://marc.info/?l=bugtraq&m=144000632319155&w=2 ([email protected])
- http://marc.info/?l=bugtraq&m=144017354030745&w=2 ([email protected])
- http://marc.info/?l=bugtraq&m=144181171013996&w=2 ([email protected])
- http://marc.info/?l=bugtraq&m=144294073801304&w=2 ([email protected])
- http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2015-1513.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2015-1514.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2015-1515.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-0078.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-0079.html ([email protected])
- http://www.debian.org/security/2015/dsa-3319 ([email protected])
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html ([email protected])
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html ([email protected])
- http://www.securityfocus.com/bid/76092 ([email protected])
- http://www.securitytracker.com/id/1033100 ([email protected])
- http://www.ubuntu.com/usn/USN-2693-1 ([email protected])
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415 ([email protected])
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480 ([email protected])
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918 ([email protected])
- https://kb.isc.org/article/AA-01272 ([email protected]) [Patch, Vendor Advisory]
- https://kb.isc.org/article/AA-01305 ([email protected])
- https://kb.isc.org/article/AA-01306 ([email protected])
- https://kb.isc.org/article/AA-01307 ([email protected])
- https://kb.isc.org/article/AA-01438 ([email protected])
- https://kb.juniper.net/JSA10783 ([email protected])
- https://kc.mcafee.com/corporate/index?page=content&id=SB10126 ([email protected])
- https://security.gentoo.org/glsa/201510-01 ([email protected])
- https://security.netapp.com/advisory/ntap-20160114-0001/ ([email protected])
- https://support.apple.com/kb/HT205032 ([email protected])
- https://www.exploit-db.com/exploits/37721/ ([email protected])
- https://www.exploit-db.com/exploits/37723/ ([email protected])
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5477 (134c704f-9b21-4f2e-91b3-4a467353bcc0)