CVE-2016-2088: Input Validation
Published Mar 9, 2016
·Updated
resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.
Affected Software
29 affected components
ISC BIND=9.10.0
ISC BIND=9.10.0-a1
ISC BIND=9.10.0-a2
ISC BIND=9.10.0-b1
ISC BIND=9.10.0-b2
ISC BIND=9.10.0-p1
ISC BIND=9.10.0-p2
ISC BIND=9.10.0-rc1
ISC BIND=9.10.0-rc2
ISC BIND=9.10.1
ISC BIND=9.10.1-b1
ISC BIND=9.10.1-b2
ISC BIND=9.10.1-p1
ISC BIND=9.10.1-p2
ISC BIND=9.10.1-rc1
ISC BIND=9.10.1-rc2
ISC BIND=9.10.2-b1
ISC BIND=9.10.2-p1
ISC BIND=9.10.2-p2
ISC BIND=9.10.2-p3
ISC BIND=9.10.2-p4
ISC BIND=9.10.2-rc1
ISC BIND=9.10.2-rc2
ISC BIND=9.10.3
ISC BIND=9.10.3-b1
ISC BIND=9.10.3-p1
ISC BIND=9.10.3-p2
ISC BIND=9.10.3-p3
ISC BIND=9.10.3-rc1
Event History
Mar 9, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2088?
CVE-2016-2088 is classified as a denial of service vulnerability that can cause the BIND service to crash.
2
How do I fix CVE-2016-2088?
To mitigate CVE-2016-2088, it is recommended to upgrade ISC BIND to version 9.10.3-P4 or later.
3
Which versions of BIND are affected by CVE-2016-2088?
CVE-2016-2088 affects ISC BIND versions 9.10.0 through 9.10.2 inclusive.
4
What type of attack does CVE-2016-2088 enable?
CVE-2016-2088 allows remote attackers to send a malformed packet that results in a denial of service via assertion failure.
5
Are DNS cookies enabled by default in affected versions of BIND for CVE-2016-2088?
Yes, DNS cookies are enabled by default in ISC BIND versions impacted by CVE-2016-2088.