Isc bind named Denial-of-Service Vulnerability (CVE-2015-5477)
Isc bind named Denial-of-Service Vulnerability (CVE-2015-5477)
Release date:
Updated on:
Affected Systems:
Isc bind <9.9.7-P2
Isc bind <9.10.2-P3
Description:
CVE (CAN) ID: CVE-2015-5477
BIND is a widely used DNS protocol.
In versions earlier than isc bind 9.9.7-P2 and earlier than 9.10.2-P3, named has a security vulnerability. Remote attackers can query the vulnerability through TKEY, this vulnerability can cause denial of service (REQUIRE assertion failure and program exit ).
<* Source: Michael McNally
Link: https://kb.isc.org/article/AA-01272
*>
Suggestion:
Vendor patch:
ISC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.isc.org/downloads
Https://kb.isc.org/article/AA-01272
This article permanently updates the link address: