CVE-2016-9778 is a medium-severity denial-of-service vulnerability affecting specific versions of ISC BIND, NetApp BIND, and related products when using the "nxdomain-redirect" feature. An attacker can trigger an assertion failure by sending a specially crafted query to a vulnerable server configured to authoritatively serve a zone while also using nxdomain-redirect for that same zone. This can lead to a server crash, resulting in high impact to availability. While the attack complexity is high, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:s1:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:s2:*:*:*:*:*:* | ||
9.9.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.8:s3:*:*:*:*:*:* | ||
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:s1:*:*:*:*:*:* | ||
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:s6:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.