CVE-2015-5722
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 34%
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
Affected products
n/a · n/aReferences
http://lists.apple.com/archives/security-announce/2015/Oct/msg00009.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168686.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165750.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165810.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165996.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167465.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html