CVE-2015-8705: ISC BIND

High severity, CVSS 7.0. EPSS: 7.7% chance of exploitation in the next 30 days.

buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.

Affected products

  • ISC BIND: version 9.0 only; version 9.0.1 only; version 9.1 only; version 9.1.1 only; version 9.1.2 only; version 9.1.3 only; …

Published 2016-01-20. Last modified 2026-06-17.