Vulnerability Name: | CVE-2016-6173 (CCN-114762) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-07-06 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2016-07-06 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-02-24 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-6173 Source: CCN Type: oss-sec Mailing List, Wed, 6 Jul 2016 12:10:19 +0200 Malicious primary DNS servers can crash secondaries Source: CCN Type: oss-sec Mailing List, Wed, 6 Jul 2016 07:03:53 -0400 (EDT) Re: Malicious primary DNS servers can crash secondaries Source: CONFIRM Type: Release Notes, Vendor Advisory http://www.nlnetlabs.nl/svn/nsd/tags/NSD_4_1_11_REL/doc/RELNOTES Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160706 Malicious primary DNS servers can crash secondaries Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160706 Re: Malicious primary DNS servers can crash secondaries Source: BID Type: Third Party Advisory, VDB Entry 91678 Source: CCN Type: BID-91678 Multiple DNS Servers Remote Denial of Service Vulnerability Source: XF Type: UNKNOWN nsd-cve20166173-dos(114762) Source: MISC Type: Third Party Advisory https://github.com/sischkg/xfer-limit/blob/master/README.md Source: MLIST Type: Third Party Advisory [dns-operations] 20160704 DNS activities in Japan Source: MLIST Type: Release Notes, Vendor Advisory [nsd-users] 20160809 NSD 4.1.11 Source: CONFIRM Type: Issue Tracking https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=790 Source: CCN Type: NLnet Labs Web site NSD | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |