CVE-2016-2776: Input Validation
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2776?
CVE-2016-2776 is classified as a denial of service vulnerability affecting ISC BIND.
How do I fix CVE-2016-2776?
To fix CVE-2016-2776, upgrade to ISC BIND versions 9.9.9-P3, 9.10.4-P3, or 9.11.0rc3 or later.
What versions of ISC BIND are affected by CVE-2016-2776?
CVE-2016-2776 affects ISC BIND versions before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3.
What can attackers do with CVE-2016-2776?
Attackers can exploit CVE-2016-2776 to create crafted queries that trigger assertion failures, leading to daemon exits and denial of service.
Which operating systems are affected by CVE-2016-2776?
CVE-2016-2776 affects various Oracle Linux and Oracle Solaris versions where ISC BIND is deployed.