Back to Database
Status published
Medium
CVE-2015-8000
db.c in named in ISC BIND 9.x before 9.9.8-P2 and...
Vulnerability Description
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-8000
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://marc.info/?l=bugtraq&m=145680832702035&w=2
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174145.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174252.html
- https://kb.isc.org/article/AA-01438
- http://rhn.redhat.com/errata/RHSA-2016-0079.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00036.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00035.html
- http://www.ubuntu.com/usn/USN-2837-1
- http://rhn.redhat.com/errata/RHSA-2015-2655.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00027.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174143.html
- https://kb.isc.org/article/AA-01380
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966
- http://www.securityfocus.com/bid/79349
- http://marc.info/?l=bugtraq&m=145680832702035&w=2
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00042.html
- http://www.securitytracker.com/id/1034418
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00034.html
- http://packetstormsecurity.com/files/134882/FreeBSD-Security-Advisory-BIND-Denial-Of-Service.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174520.html
- https://kb.isc.org/article/AA-01317
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04923105
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00028.html
- http://rhn.redhat.com/errata/RHSA-2016-0078.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html
- http://rhn.redhat.com/errata/RHSA-2015-2656.html
- http://rhn.redhat.com/errata/RHSA-2015-2658.html
- http://www.debian.org/security/2015/dsa-3420
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
More from oracle
View All →CVE-2021-3314
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A...
Medium
6.1
CVE-2020-9315
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web...
High
7.5
CVE-2020-9314
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web...
Medium
4.8
CVE-2019-2413
Vulnerability in the Oracle Reports Developer component of Oracle Fusion...
Medium
6.1
CVE-2018-3209
Vulnerability in the Java SE component of Oracle Java SE...
High
8.3
Affected Vendor
oracle
View all reports →Affected Software
linux, solaris, vm server, bind
Vulnerable Versions:
5.0, 6, 7, 10, 11.3, 3.2, 8.4.7, 9.0, 9.0.1, 9.1, 9.1.1, 9.1.2, 9.1.3, 9.2, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.2.5, 9.2.6, 9.2.7, 9.3, 9.3.0, 9.3.1, 9.3.2, 9.3.3, 9.4, 9.4.0, 9.4.1, 9.4.2, 9.4.3, 9.5, 9.5.0, 9.5.1, 9.5.2, 9.5.3, 9.6, 9.6.0, 9.6.1, 9.6.2, 9.6.3, 9.7.0, 9.7.1, 9.7.2, 9.7.3, 9.7.4, 9.7.5, 9.7.6, 9.7.7, 9.8.0, 9.8.1, 9.8.2, 9.8.3, 9.8.4, 9.8.5, 9.8.6, 9.9.0, 9.9.1, 9.9.2, 9.9.3, 9.9.4, 9.9.5, 9.9.6, 9.9.7, 9.9.8, 9.10.0, 9.10.1, 9.10.2, 9.10.3
Timeline
Official Publish:
December 16th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.