CVE-2015-8704

apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
iscbind
9.0
iscbind
9.0.1
iscbind
9.1
iscbind
9.1.1
iscbind
9.1.2
iscbind
9.1.3
iscbind
9.2
iscbind
9.2.0
iscbind
9.2.1
iscbind
9.2.2
iscbind
9.2.2:p3
iscbind
9.2.3
iscbind
9.2.4
iscbind
9.2.5
iscbind
9.2.6
iscbind
9.2.7
iscbind
9.3
iscbind
9.3.0
iscbind
9.3.1
iscbind
9.3.2
iscbind
9.3.3
iscbind
9.4
iscbind
9.4.0
iscbind
9.4.0:rc1
iscbind
9.4.1
iscbind
9.4.2
iscbind
9.4.3
iscbind
9.4.3:rc1
iscbind
9.5
iscbind
9.5.0
iscbind
9.5.0:rc1
iscbind
9.5.1
iscbind
9.5.1:rc1
iscbind
9.5.1:rc2
iscbind
9.5.2
iscbind
9.5.2:rc1
iscbind
9.5.3
iscbind
9.5.3:rc1
iscbind
9.6
iscbind
9.6:r5_p1
iscbind
9.6:r6_b1
iscbind
9.6:r6_rc1
iscbind
9.6:r6_rc2
iscbind
9.6:r7_p1
iscbind
9.6:r7_p2
iscbind
9.9.8:p2
iscbind
9.10.1
iscbind
9.10.1:p1
iscbind
9.10.2
iscbind
9.10.2:b1
iscbind
9.10.2:p1
iscbind
9.10.2:p2
iscbind
9.10.2:p3
iscbind
9.10.2:p4
iscbind
9.10.2:rc1
iscbind
9.10.3
iscbind
9.10.3:p1
iscbind
9.10.3:p2
iscbind
9.10.3:rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bind9
bullseye
1:9.16.50-1~deb11u2
fixed
bullseye (security)
1:9.16.50-1~deb11u1
fixed
bookworm
1:9.18.28-1~deb12u2
fixed
bookworm (security)
1:9.18.28-1~deb12u2
fixed
sid
1:9.20.2-1
fixed
trixie
1:9.20.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bind9
wily
Fixed 1:9.9.5.dfsg-11ubuntu1.2
released
vivid
Fixed 1:9.9.5.dfsg-9ubuntu0.5
released
trusty
Fixed 1:9.9.5.dfsg-3ubuntu0.7
released
precise
Fixed 1:9.8.1.dfsg.P1-4ubuntu0.15
released
References