CVE-2016-1286 is a high-severity denial-of-service vulnerability affecting ISC BIND versions 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4, as well as various distributions like Debian, Fedora, and SUSE. A remote attacker can trigger an assertion failure and daemon exit by sending a crafted signature record for a DNAME record. With a CVSS score of 8.6 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability. While no public exploit code or active exploitation has been observed, its high FAUCET Risk Score of 97/100 and media coverage indicate significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.10.0, < 9.10.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:-:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:p2:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:p3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.