CVE-2015-8000 describes a denial-of-service vulnerability in ISC BIND versions 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2, affecting various operating systems including Linux and Solaris. A remote attacker can trigger an assertion failure and daemon exit by sending a malformed class attribute. With a CVSS score of 5.0, this vulnerability has a low attack complexity and requires no authentication, leading to a complete loss of availability. While not actively exploited in the wild and lacking public exploit code, its high FAUCET Risk Score and notable community discussion suggest it warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.