CVE-2016-2088

Source
https://cve.org/CVERecord?id=CVE-2016-2088
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-2088.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-2088
Downstream
Related
Published
2016-03-09T23:59:04.493Z
Modified
2026-04-16T01:42:27.199679098Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.

References

Affected packages

Git / gitlab.isc.org/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://gitlab.isc.org/isc-projects/bind9
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:isc:bind:9.10.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:a1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:a2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:b1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:b2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:p1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:p2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.0:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:b1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:b2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:p1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:p2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.1:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:b1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:p1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:p2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:p3:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:p4:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:rc1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.2:rc2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.3:b1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.3:p1:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.3:p2:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.3:p3:*:*:*:*:*:*",
        "cpe:2.3:a:isc:bind:9.10.3:rc1:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "9.10.0"
        },
        {
            "last_affected": "9.10.0-a1"
        },
        {
            "last_affected": "9.10.0-a2"
        },
        {
            "last_affected": "9.10.0-b1"
        },
        {
            "last_affected": "9.10.0-b2"
        },
        {
            "last_affected": "9.10.0-p1"
        },
        {
            "last_affected": "9.10.0-p2"
        },
        {
            "last_affected": "9.10.0-rc1"
        },
        {
            "last_affected": "9.10.0-rc2"
        },
        {
            "last_affected": "9.10.1"
        },
        {
            "last_affected": "9.10.1-b1"
        },
        {
            "last_affected": "9.10.1-b2"
        },
        {
            "last_affected": "9.10.1-p1"
        },
        {
            "last_affected": "9.10.1-p2"
        },
        {
            "last_affected": "9.10.1-rc1"
        },
        {
            "last_affected": "9.10.1-rc2"
        },
        {
            "last_affected": "9.10.2-b1"
        },
        {
            "last_affected": "9.10.2-p1"
        },
        {
            "last_affected": "9.10.2-p2"
        },
        {
            "last_affected": "9.10.2-p3"
        },
        {
            "last_affected": "9.10.2-p4"
        },
        {
            "last_affected": "9.10.2-rc1"
        },
        {
            "last_affected": "9.10.2-rc2"
        },
        {
            "last_affected": "9.10.3"
        },
        {
            "last_affected": "9.10.3-b1"
        },
        {
            "last_affected": "9.10.3-p1"
        },
        {
            "last_affected": "9.10.3-p2"
        },
        {
            "last_affected": "9.10.3-p3"
        },
        {
            "last_affected": "9.10.3-rc1"
        }
    ],
    "source": "CPE_FIELD"
}

Affected versions

v9.*
v9.10.0
v9.10.0a1
v9.10.0a2
v9.10.0b1
v9.10.0b2
v9.10.0rc1
v9.10.0rc2
v9.10.1
v9.10.1b1
v9.10.1b2
v9.10.1rc1
v9.10.1rc2
v9.10.2
v9.10.2-P1
v9.10.2-P2
v9.10.2-P3
v9.10.2-P4
v9.10.2b1
v9.10.2rc1
v9.10.2rc2
v9.10.3
v9.10.3-P2
v9.10.3-P3
v9.10.3b1
v9.10.3rc1
v9.5.0a1
v9.5.0a2
v9.5.0a3
v9.5.0a4
v9.5.0a5
v9.5.0a6
v9.7.0a1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-2088.json"