CVE-2022-3080
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/09/2022
Last modified:
03/07/2024
Description
By sending specific queries to the resolver, an attacker can cause named to crash.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | 9.16.14 (including) | 9.16.33 (excluding) |
| cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | 9.18.0 (including) | 9.18.7 (excluding) |
| cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | 9.19.0 (including) | 9.19.5 (excluding) |
| cpe:2.3:a:isc:bind:9.16.14:s1:*:*:supported_preview:*:*:* | ||
| cpe:2.3:a:isc:bind:9.16.21:s1:*:*:supported_preview:*:*:* | ||
| cpe:2.3:a:isc:bind:9.16.32:s1:*:*:supported_preview:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2022/09/21/3
- https://kb.isc.org/docs/cve-2022-3080
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20240621-0002/
- https://www.debian.org/security/2022/dsa-5235



