ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact Complete
AV:N/AC:L/Au:N/C:P/I:N/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Isc |
|
Redhat |
|
Configuration 1 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat Enterprise Linux 4 Extended Lifecycle Support | |||
bind-20:9.2.4-39.el4 | cpe:/o:redhat:rhel_els:4 | RHSA-2012:1110 | 2012-07-23T00:00:00Z |
Red Hat Enterprise Linux 5 | |||
bind-30:9.3.6-20.P1.el5_8.1 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2012:0716 | 2012-06-07T00:00:00Z |
bind97-32:9.7.0-10.P2.el5_8.1 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2012:0717 | 2012-06-07T00:00:00Z |
Red Hat Enterprise Linux 6 | |||
bind-32:9.7.3-8.P3.el6_2.3 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2012:0716 | 2012-06-07T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2012-06-05T16:00:00
Updated: 2024-08-06T19:01:02.980Z
Reserved: 2012-03-15T00:00:00
Link: CVE-2012-1667
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-06-05T16:55:01.277
Modified: 2024-11-21T01:37:25.553
Link: CVE-2012-1667
Redhat