CVE-2016-1285 describes a denial-of-service vulnerability in ISC BIND versions 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4, where improper handling of DNAME records in fetch reply messages can lead to an assertion failure and daemon exit. This critical flaw affects various distributions including Canonical, Debian, Fedora, Juniper, OpenSUSE, and SUSE. Rated with a CVSS score of 6.8 (Medium), this vulnerability allows remote, unauthenticated attackers to trigger a denial of service by sending a malformed packet to the rndc control channel, albeit with high attack complexity. The FAUCET Risk Score is 71.0/100, and its EPSS score is notably high, indicating a significant threat to availability. While not listed on the CISA KEV for active exploitation and lacking public exploit code, it is marked as "Active" on a general threat hotlist and has garnered community attention with 25 mentions and a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.10.0, < 9.10.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:-:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:p2:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:p3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.