CVE-2015-8705: Input Validation
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8705?
CVE-2015-8705 has a severity rating that indicates it can lead to denial of service due to assertion failure or daemon crash when debug logging is enabled.
How do I fix CVE-2015-8705?
To fix CVE-2015-8705, upgrade ISC BIND to version 9.10.3-P3 or later where the vulnerability is resolved.
What can be exploited in CVE-2015-8705?
CVE-2015-8705 can be exploited through crafted OPT data or ECS options which may trigger assertion failures.
Who is impacted by CVE-2015-8705?
Organizations using ISC BIND versions 9.10.x before 9.10.3-P3 with debug logging enabled are impacted by CVE-2015-8705.
What type of vulnerability is CVE-2015-8705?
CVE-2015-8705 is classified as a denial of service vulnerability due to its potential to crash the BIND daemon.