CVE-2016-9131 is a denial-of-service vulnerability affecting ISC BIND versions 9.9.9-P5, 9.10.4-P5, and 9.11.0-P2 and earlier, specifically impacting Debian, ISC, NetApp, and Red Hat products. Rated with a CVSS score of 7.5 (High), this vulnerability allows remote, unauthenticated attackers to trigger an assertion failure and daemon exit by sending a malformed response to an RTYPE ANY query. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community attention and media coverage, indicating its potential impact despite not being actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, <= 9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.10.0, <= 9.10.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:-:*:*:*:*:*:* | ||
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:b1:*:*:*:*:*:* | ||
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:b2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.