---
id: CVE-2015-5477
title: >-
  named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows
  remote attackers to cause a denial of service (REQUIRE assertion failure and
  daemon exit) via TKEY queries.
summary: >-
  named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows
  remote attackers to cause a denial of service (REQUIRE assertion failure and
  daemon exit) via TKEY queries.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-19
  - CWE-617
vendor: oracle
product: vm_server
affected:
  - junos < 12.1
  - 'junos >= 13.1, < 13.2'
  - junos = 12.1
  - junos = 12.1r
  - junos = 12.1x44
  - junos = 12.1x45
  - junos = 12.1x46
  - junos = 12.1x47
  - junos = 12.3
  - junos = 12.3x48
  - junos = 12.3x50
  - junos = 13.2
  - junos = 13.2x51
  - junos = 14.1
  - junos = 14.1x50
  - junos = 14.1x51
  - junos = 14.1x53
  - junos = 14.2
  - junos = 15.1
  - junos = 15.1x49
  - junos = 15.1x53
  - fedora = 21
  - fedora = 22
  - enterprise_linux = 5.0
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux_aus = 6.4
  - enterprise_linux_aus = 6.5
  - enterprise_linux_aus = 6.6
  - debian_linux = 7.0
  - debian_linux = 8.0
  - vm_server = 3.2
  - solaris = 10
  - solaris = 11.2
  - hp-ux = 11.11
  - hp-ux = 11.23
  - hp-ux = 11.31
  - ubuntu_linux = 12.04
  - clustered_data_ontap
  - os_x_server = 4.1.5
  - dns = 9.2.3
  - dns = 9.3
  - openvms = 5.7
  - vcx < 9.8.18
  - linux_enterprise_debuginfo = 11
  - evergreen = 11.4
  - opensuse = 13.1
  - opensuse = 13.2
  - linux_enterprise_desktop = 11
  - linux_enterprise_desktop = 12
  - linux_enterprise_server = 10
  - linux_enterprise_server = 11
  - linux_enterprise_server = 12
  - linux_enterprise_software_development_kit = 11
  - linux_enterprise_software_development_kit = 12
  - 'bind >= 9.1.0, < 9.9.7'
  - 'bind >= 9.10.0, < 9.10.2'
  - bind = 9.10.2
patched:
  - junos 13.2
  - vcx 9.8.18
  - bind 9.10.2
published: '2015-07-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T19:12:37.977'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2015-5477'
references:
  - url: 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718'
    label: cve@mitre.org
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html
    label: cve@mitre.org
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html
    label: cve@mitre.org
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html'
    label: cve@mitre.org
  - url: 'http://marc.info/?l=bugtraq&m=144000632319155&w=2'
    label: cve@mitre.org
  - url: 'http://marc.info/?l=bugtraq&m=144017354030745&w=2'
    label: cve@mitre.org
  - url: 'http://marc.info/?l=bugtraq&m=144181171013996&w=2'
    label: cve@mitre.org
  - url: 'http://marc.info/?l=bugtraq&m=144294073801304&w=2'
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1513.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1514.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1515.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-0078.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-0079.html'
    label: cve@mitre.org
  - url: 'http://www.debian.org/security/2015/dsa-3319'
    label: cve@mitre.org
  - url: >-
      http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
    label: cve@mitre.org
  - url: >-
      http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/76092'
    label: cve@mitre.org
  - url: 'http://www.securitytracker.com/id/1033100'
    label: cve@mitre.org
  - url: 'http://www.ubuntu.com/usn/USN-2693-1'
    label: cve@mitre.org
  - url: >-
      https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415
    label: cve@mitre.org
  - url: >-
      https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
    label: cve@mitre.org
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918
    label: cve@mitre.org
  - url: 'https://kb.isc.org/article/AA-01272'
    label: cve@mitre.org
  - url: 'https://kb.isc.org/article/AA-01305'
    label: cve@mitre.org
  - url: 'https://kb.isc.org/article/AA-01306'
    label: cve@mitre.org
  - url: 'https://kb.isc.org/article/AA-01307'
    label: cve@mitre.org
  - url: 'https://kb.isc.org/article/AA-01438'
    label: cve@mitre.org
  - url: 'https://kb.juniper.net/JSA10783'
    label: cve@mitre.org
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10126'
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/201510-01'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20160114-0001/'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT205032'
    label: cve@mitre.org
  - url: 'https://www.exploit-db.com/exploits/37721/'
    label: cve@mitre.org
  - url: 'https://www.exploit-db.com/exploits/37723/'
    label: cve@mitre.org
  - url: 'http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=144000632319155&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=144017354030745&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=144181171013996&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=144294073801304&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1513.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1514.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1515.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-0078.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-0079.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2015/dsa-3319'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/76092'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1033100'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-2693-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.isc.org/article/AA-01272'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.isc.org/article/AA-01305'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.isc.org/article/AA-01306'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.isc.org/article/AA-01307'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.isc.org/article/AA-01438'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.juniper.net/JSA10783'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10126'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/201510-01'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20160114-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT205032'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/37721/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/37723/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5477
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2015/cve-2015-5477.json
  - url: 'https://access.redhat.com/security/cve/CVE-2015-5477'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1247361'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2015-5477'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2015-5477'
  - url: 'https://access.redhat.com/solutions/1548963'
  - url: 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog'
  - url: 'https://access.redhat.com/errata/RHSA-2015:1514'
  - url: 'https://access.redhat.com/errata/RHSA-2015:1515'
  - url: 'https://access.redhat.com/errata/RHSA-2015:1513'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0079'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0078'
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.91807
epssPercentile: 0.99816
kev: true
kevDateAdded: '2026-10-08'
kevDueDate: '2026-10-11'
kevRansomware: false
exploited: true
exploits:
  exploitdb: true
  github: 7
  githubRepos:
    - 'https://github.com/robertdavidgraham/cve-2015-5477'
    - 'https://github.com/elceef/tkeypoc'
    - 'https://github.com/hmlio/vaas-cve-2015-5477'
  metasploit:
    - auxiliary/dos/dns/bind_tkey
  checkedAt: '2026-10-09T20:12:00.505Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-08T17:40:04.174602Z'
ingestedAt: '2026-10-08T17:56:11.731Z'
---

## Overview

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

## Affected

- `junos < 12.1`
- `junos >= 13.1, < 13.2`
- `junos = 12.1`
- `junos = 12.1r`
- `junos = 12.1x44`
- `junos = 12.1x45`
- `junos = 12.1x46`
- `junos = 12.1x47`
- `junos = 12.3`
- `junos = 12.3x48`
- `junos = 12.3x50`
- `junos = 13.2`
- `junos = 13.2x51`
- `junos = 14.1`
- `junos = 14.1x50`
- `junos = 14.1x51`
- `junos = 14.1x53`
- `junos = 14.2`
- `junos = 15.1`
- `junos = 15.1x49`
- `junos = 15.1x53`
- `fedora = 21`
- `fedora = 22`
- `enterprise_linux = 5.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux_aus = 6.4`
- `enterprise_linux_aus = 6.5`
- `enterprise_linux_aus = 6.6`
- `debian_linux = 7.0`
- `debian_linux = 8.0`
- `vm_server = 3.2`
- `solaris = 10`
- `solaris = 11.2`
- `hp-ux = 11.11`
- `hp-ux = 11.23`
- `hp-ux = 11.31`
- `ubuntu_linux = 12.04`
- `clustered_data_ontap`
- `os_x_server = 4.1.5`
- `dns = 9.2.3`
- `dns = 9.3`
- `openvms = 5.7`
- `vcx < 9.8.18`
- `linux_enterprise_debuginfo = 11`
- `evergreen = 11.4`
- `opensuse = 13.1`
- `opensuse = 13.2`
- `linux_enterprise_desktop = 11`
- `linux_enterprise_desktop = 12`
- `linux_enterprise_server = 10`
- `linux_enterprise_server = 11`
- `linux_enterprise_server = 12`
- `linux_enterprise_software_development_kit = 11`
- `linux_enterprise_software_development_kit = 12`
- `bind >= 9.1.0, < 9.9.7`
- `bind >= 9.10.0, < 9.10.2`
- `bind = 9.10.2`

## Remediation

Upgrade past the affected range:

- `junos 13.2`
- `vcx 9.8.18`
- `bind 9.10.2`

## Vendor advisories

- **RHSA-2015:1514** · Red Hat · fixed in: Red Hat Enterprise Linux Desktop (v. 5 client), Red Hat Enterprise Linux Desktop Workstation (v. 5 client), Red Hat Enterprise Linux (v. 5 server) · released 2015-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2015:1514)
- **RHSA-2015:1515** · Red Hat · fixed in: Red Hat Enterprise Linux Desktop Workstation (v. 5 client), Red Hat Enterprise Linux (v. 5 server) · released 2015-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2015:1515)
- **RHSA-2015:1513** · Red Hat · fixed in: Red Hat Enterprise Linux Desktop (v. 6), Red Hat Enterprise Linux Desktop Optional (v. 6), Red Hat Enterprise Linux HPC Node (v. 6), Red Hat Enterprise Linux HPC Node Optional (v. 6), Red Hat Enterprise Linux Server (v. 6), Red Hat Enterprise Linux Server Optional (v. 6), … · released 2015-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2015:1513)
- **RHSA-2016:0079** · Red Hat · fixed in: Red Hat Enterprise Linux HPC Node EUS (v. 6.6), Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.6), Red Hat Enterprise Linux Server EUS (v. 6.6), Red Hat Enterprise Linux Server Optional EUS (v. 6.6) · released 2016-01-28 · [advisory](https://access.redhat.com/errata/RHSA-2016:0079)
- **RHSA-2016:0078** · Red Hat · fixed in: Red Hat Enterprise Linux Server AUS (v. 6.4), Red Hat Enterprise Linux Server AUS (v. 6.5), Red Hat Enterprise Linux Server Optional AUS (v. 6.4), Red Hat Enterprise Linux Server Optional AUS (v. 6.5) · released 2016-01-28 · [advisory](https://access.redhat.com/errata/RHSA-2016:0078)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 4 · no fix planned: Red Hat Enterprise Linux 4 · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2015/cve-2015-5477.json)
