CVE-2016-2776
84Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 89%
from disclosure to weapon0 days
Published on NVDSep 28
1st PoCSep 28
metasploitSep 27
VulnCheck+7d
exploitation probability
89%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
Affected products
n/a · n/apublic PoCs found — 5
exploitdbwww.exploit-db.com/exploits/40453unverifiedgithubgithub.com/infobyte/CVE-2016-2776★ 27githubgithub.com/KosukeShimofuji/CVE-2016-2776★ 0cve_referencewww.exploit-db.com/exploits/40453/unverifiedvulncheckvulncheck.com/xdb/63841840badbunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://rhn.redhat.com/errata/RHSA-2016-1944.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1945.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2099.htmlhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107https://kb.isc.org/article/AA-01419/0https://kb.isc.org/article/AA-01435https://kb.isc.org/article/AA-01436https://kb.isc.org/article/AA-01438https://security.FreeBSD.org/advisories/FreeBSD-SA-16:28.bind.aschttps://security.gentoo.org/glsa/201610-07https://security.netapp.com/advisory/ntap-20160930-0001/https://www.exploit-db.com/exploits/40453/