VulnerabilityModified
CVE-2011-2464
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
MEDIUM 5.0EPSS 19.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 19.27% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- isc/bind
- Source
- cve@mitre.org
References
- http://blogs.oracle.com/sunsecurity/entry/cve_2011_2464_remote_denial
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062522.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062846.html
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00006.html
- http://marc.info/?l=bugtraq&m=131983337229394&w=2
- http://osvdb.org/73605
- http://secunia.com/advisories/45082Vendor Advisory
- http://secunia.com/advisories/45089
- http://secunia.com/advisories/45143
- http://secunia.com/advisories/45177
- http://secunia.com/advisories/45185Vendor Advisory
- http://secunia.com/advisories/45223
- http://secunia.com/advisories/45410
- http://secunia.com/advisories/45412
- http://support.apple.com/kb/HT5002
- http://www.debian.org/security/2011/dsa-2272
- http://www.isc.org/software/bind/advisories/cve-2011-2464
- http://www.kb.cert.org/vuls/id/142646US Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:115
- http://www.redhat.com/support/errata/RHSA-2011-0926.html
- http://www.securityfocus.com/archive/1/518749/100/0/threaded
- http://www.securityfocus.com/bid/48566
- http://www.securitytracker.com/id?1025742
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.377171
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68375
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13997
- https://www.ubuntu.com/usn/USN-1163-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.