CVE-2015-8704
Publication date 19 January 2016
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
Status
Package | Ubuntu Release | Status |
---|---|---|
bind9 | ||
14.04 LTS trusty |
Fixed 1:9.9.5.dfsg-3ubuntu0.7
|
|
Notes
jdstrand
these missed OTA9 in vivid/stable-phone-overlay and should be included in OTA9.5 via https://launchpad.net/~ci-train-ppa-service/+archive/ubuntu/stable-snapshot/+packages landed in rc-proposed in r385 on krillin: http://people.canonical.com/~lzemczak/landing-team/ubuntu-touch/rc-proposed/ubuntu/krillin/385.commitlog
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-2874-1
- Bind vulnerability
- 19 January 2016