mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
204 lines
7.3 KiB
JSON
204 lines
7.3 KiB
JSON
{
|
|
"id": "CVE-2016-9778",
|
|
"sourceIdentifier": "security-officer@isc.org",
|
|
"published": "2019-01-16T20:29:00.253",
|
|
"lastModified": "2019-10-09T23:20:43.727",
|
|
"vulnStatus": "Modified",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the \"nxdomain-redirect\" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type \"redirect\" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Un error a la hora de manejar ciertas consultas puede provocar un fallo de aserci\u00f3n cuando un servidor emplea la caracter\u00edstica nxdomain-redirect para cubrir una zona para la que tambi\u00e9n est\u00e1 prestando servicios autoritativos. Un servidor vulnerable podr\u00eda ser detenido de forma intencional por un atacante si est\u00e1 empleando una configuraci\u00f3n que cumple los criterios para la vulnerabilidad y si el atacante puede provocar que acepte una consulta que posee los atributos necesarios. N\u00f3tese: esta vulnerabilidad afecta a la caracter\u00edstica \"nxdomain-redirect\", que es uno de los dos m\u00e9todos para gestionar la redirecci\u00f3n de NXDOMAIN y solo est\u00e1 disponible en ciertas versiones de BIND. La redirecci\u00f3n mediante zonas de tipo \"redirect\" no se ha visto afectada por esta vulnerabilidad. Afecta a BIND desde la versi\u00f3n 9.9.8-S1 hasta la 9.9.8-S3, desde la versi\u00f3n 9.9.9-S1 hasta la 9.9.9-S6 y a la versi\u00f3n 9.11.0-9.11.0-P1."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV30": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.0",
|
|
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "HIGH",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 5.9,
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
"exploitabilityScore": 2.2,
|
|
"impactScore": 3.6
|
|
},
|
|
{
|
|
"source": "security-officer@isc.org",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.0",
|
|
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 7.5,
|
|
"baseSeverity": "HIGH"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 3.6
|
|
}
|
|
],
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "PARTIAL",
|
|
"baseScore": 4.3
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-388"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.9.8:s1:*:*:*:*:*:*",
|
|
"matchCriteriaId": "52C0DC21-D024-4ABD-910B-3C6A9A04C8B2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.9.8:s2:*:*:*:*:*:*",
|
|
"matchCriteriaId": "72392A81-BBFE-419F-84D1-2376CB552213"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.9.8:s3:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BBB98AAF-3EA6-47AD-949D-FBAC04AEC28E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.9.9:s1:*:*:*:*:*:*",
|
|
"matchCriteriaId": "21FBF6B7-BA47-46AC-B7EB-3A3A2E985BFD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.9.9:s6:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A7A167E4-4CAF-4FD7-92F0-986F1C12F4CD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.11.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3160C5ED-75EA-47B2-998E-EDFC46B37DDA"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:isc:bind:9.11.0:p1:*:*:*:*:*:*",
|
|
"matchCriteriaId": "086C327B-DF9F-4D4E-A538-1E29FEDC34C5"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E0C4B1E5-75BF-43AE-BBAC-0DD4124C71ED"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:netapp:solidfire_element_os_management_node:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6AD8D649-8F3E-4B22-912C-FE94CDC88A67"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/95388",
|
|
"source": "security-officer@isc.org",
|
|
"tags": [
|
|
"Third Party Advisory",
|
|
"VDB Entry"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.securitytracker.com/id/1037582",
|
|
"source": "security-officer@isc.org",
|
|
"tags": [
|
|
"Third Party Advisory",
|
|
"VDB Entry"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://kb.isc.org/article/AA-01442/",
|
|
"source": "security-officer@isc.org",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://security.gentoo.org/glsa/201708-01",
|
|
"source": "security-officer@isc.org",
|
|
"tags": [
|
|
"Third Party Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://security.netapp.com/advisory/ntap-20180926-0005/",
|
|
"source": "security-officer@isc.org",
|
|
"tags": [
|
|
"Third Party Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |