Vulnerability Name: | CVE-2022-1183 (CCN-226867) | ||||||||||||
Assigned: | 2022-05-18 | ||||||||||||
Published: | 2022-05-18 | ||||||||||||
Updated: | 2022-10-07 | ||||||||||||
Summary: | On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-617 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-1183 Source: XF Type: UNKNOWN isc-cve20221183-dos(226867) Source: CONFIRM Type: Vendor Advisory https://kb.isc.org/docs/cve-2022-1183 Source: CCN Type: ISC Web site CVE-2022-1183: Destroying a TLS session early causes assertion failure Source: CCN Type: oss-sec Mailing List, Wed, 18 May 2022 15:38:36 +0100 ISC has disclosed a vulnerability in BIND (CVE-2022-1183) Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20220707-0002/ | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration 6: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |