CVE-2015-5477: High severity isc bind 9 vulnerability
Published Jul 29, 2015
·Updated
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
Affected Software
2 affected components
ISC BIND<=9.9.7
ISC BIND<=9.10.2
Remediation
Patch Available
Event History
Jul 29, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5477?
CVE-2015-5477 has a severity rating of high due to its potential to cause denial of service.
2
How do I fix CVE-2015-5477?
To fix CVE-2015-5477, upgrade ISC BIND to version 9.9.7-P2 or later, or 9.10.2-P3 or later.
3
Which versions of ISC BIND are affected by CVE-2015-5477?
ISC BIND versions prior to 9.9.7-P2 and 9.10.2-P3 are affected by CVE-2015-5477.
4
What attack vector is exploited in CVE-2015-5477?
CVE-2015-5477 is exploited through TKEY queries that lead to a REQUIRE assertion failure.
5
Can CVE-2015-5477 lead to data loss?
CVE-2015-5477 does not directly cause data loss but can result in interruption of service.