Candidate: CVE-2016-2088 CRD: 2016-03-09 20:00:00 UTC PublicDate: 2016-03-09 23:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2088 https://kb.isc.org/article/AA-01351 Description: resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option. Ubuntu-Description: Notes: mdeslaur> 9.10.x only Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H [6.8 MEDIUM] Patches_bind9: upstream_bind9: released (9.9.8-P4, 9.10.3-P4) precise_bind9: not-affected trusty_bind9: not-affected trusty/esm_bind9: not-affected vivid/stable-phone-overlay_bind9: not-affected vivid/ubuntu-core_bind9: not-affected wily_bind9: not-affected (1:9.9.5.dfsg-11ubuntu1.2) devel_bind9: not-affected (1:9.10.3.dfsg.P4-1)