CVE-2015-5722: Input Validation
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5722?
CVE-2015-5722 has a high severity rating as it allows remote attackers to cause a denial of service.
How do I fix CVE-2015-5722?
To fix CVE-2015-5722, upgrade ISC BIND to version 9.9.7-P3 or 9.10.2-P4 or later.
What software is affected by CVE-2015-5722?
CVE-2015-5722 affects ISC BIND versions 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4, as well as Apple Mac OS X Server 5.0.15.
What type of attack is associated with CVE-2015-5722?
CVE-2015-5722 is associated with a denial of service attack through crafted DNS queries.
Can CVE-2015-5722 impact my DNS server?
Yes, if your DNS server is running the affected versions of ISC BIND or Apple Mac OS X Server, it is vulnerable to CVE-2015-5722.