CVE-2015-5477
Aliases:DEBIAN-CVE-2015-5477
Advisory lineage Upstream: 0 Downstream: 15
Modified
Published: 29 Jul 2015, 14:00
Last modified:08 Oct 2026, 19:58
Vulnerability Summary
Overall Risk (default)
high
59/100 CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
91.28% CRITICAL
91% probability -1.47%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected
Timeline
29 Jul 2015, 14:00
Published
Vulnerability first disclosed
08 Oct 2026, 00:00
Added to CISA KEV
ISC BIND Data Processing Errors Vulnerability
08 Oct 2026, 19:58
Last Modified
Vulnerability information updated
11 Oct 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Description
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•HIGH•Score: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 91.28%• Percentile: 100%
Techniques & Countermeasures
- CWE-19•Data Processing Errors
Weaknesses in this category are typically found in functionality that processes data. Data processing is the manipulation of input to retrieve or save information.
- CWE-617•Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Affected Systems
- debian•bind9
< 1:9.9.5.dfsg-11 | < 1:9.9.5.dfsg-11 | < 1:9.9.5.dfsg-11 | < 1:9.9.5.dfsg-11
- isc•bind
≤ 9.9.7 | ≤ 9.10.2
References (44)
- http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415
- https://kb.juniper.net/JSA10783
- http://rhn.redhat.com/errata/RHSA-2015-1513.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
- https://security.netapp.com/advisory/ntap-20160114-0001/
- https://kb.isc.org/article/AA-01438
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html
- http://marc.info/?l=bugtraq&m=144017354030745&w=2
- http://marc.info/?l=bugtraq&m=144294073801304&w=2
- http://rhn.redhat.com/errata/RHSA-2016-0079.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718
- http://rhn.redhat.com/errata/RHSA-2015-1514.html
- http://www.ubuntu.com/usn/USN-2693-1
- https://support.apple.com/kb/HT205032
- http://www.securitytracker.com/id/1033100
- https://kb.isc.org/article/AA-01307
- http://www.securityfocus.com/bid/76092
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
- https://www.exploit-db.com/exploits/37721/
- http://rhn.redhat.com/errata/RHSA-2015-1515.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
- https://security.gentoo.org/glsa/201510-01
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
- http://marc.info/?l=bugtraq&m=144181171013996&w=2
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
- http://www.debian.org/security/2015/dsa-3319
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html
- http://marc.info/?l=bugtraq&m=144000632319155&w=2
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html
- https://www.exploit-db.com/exploits/37723/
- https://kb.isc.org/article/AA-01305
- http://rhn.redhat.com/errata/RHSA-2016-0078.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html
- https://kb.isc.org/article/AA-01306
- https://kc.mcafee.com/corporate/index?page=content&id=SB10126
- https://kb.isc.org/article/AA-01272
- https://security-tracker.debian.org/tracker/CVE-2015-5477
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5477