CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
- Affected products
- Alt Linux, Bind Server, Centos, Freebsd, Ibm Aix, Isc Bind 9.X, Junos, Red Hat
- Isc Bind
- < 9.9.8, 9.10.3
- Fix
- Available
- CVSS 3.1
- 6.8 MEDIUM
- EPSS
- 59.1% (99th percentile)
- NVD status
- Modified
- Published
- 2016-03-09
CVE-2016-1285 at NVD
No indexed exploits for CVE-2016-1285 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2016-1285 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.