CVE-2016-6170
Description
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (primary DNS server crash) via a large UPDATE message.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-6170
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-6170.html
Vendor advisory: secalert@redhat.com — https://kb.isc.org/article/AA-01390/169/CVE-2016-6170
Vendor advisory: secalert@redhat.com — https://kb.isc.org/article/AA-01390
Vendor advisory: secalert@redhat.com — https://github.com/sischkg/xfer-limit/blob/master/README.md
Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1353563
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1:9.10.6+dfsg-1 |
| debian | bullseye | fixed | 1:9.10.6+dfsg-1 |
| debian | forky | fixed | 1:9.10.6+dfsg-1 |
| debian | sid | fixed | 1:9.10.6+dfsg-1 |
| debian | trixie | fixed | 1:9.10.6+dfsg-1 |
| sles | affected | | |
| rhel | 5.0 | affected | |
| rhel | 6.0 | affected | |
| rhel | 7.0 | affected | |
References
- http://www.openwall.com/lists/oss-security/2016/07/06/3
- http://www.securityfocus.com/bid/91611
- http://www.securitytracker.com/id/1036241
- https://bugzilla.redhat.com/show_bug.cgi?id=1353563
- https://github.com/sischkg/xfer-limit/blob/master/README.md
- https://kb.isc.org/article/AA-01390
- https://kb.isc.org/article/AA-01390/169/CVE-2016-6170
- https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html
- https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015073.html
- https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015075.html
- https://security.gentoo.org/glsa/201610-07
- https://www.suse.com/security/cve/CVE-2016-6170.html
- https://security-tracker.debian.org/tracker/CVE-2016-6170
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.