PT-2018-2730 · Isc+6 · Bind+6

Publicado

2016-09-28

·

Atualizado

2022-05-10

·

CVE-2018-5740

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.7.0 through 9.8.8 BIND versions 9.9.0 through 9.9.13 BIND versions 9.10.0 through 9.10.8 BIND versions 9.11.0 through 9.11.4 BIND versions 9.12.0 through 9.12.2 BIND versions 9.13.0 through 9.13.2
Description The issue is related to the "deny-answer-aliases" feature in the BIND DNS server, which is intended to protect against DNS rebinding attacks. However, a defect in this feature can cause an assertion failure in name.c, leading to a denial of service. This can be exploited by a remote attacker. The feature is little-used and only servers with the feature explicitly enabled are at risk.
Recommendations To resolve the issue for BIND versions 9.7.0 through 9.8.8, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.9.0 through 9.9.13, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.10.0 through 9.10.8, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.11.0 through 9.11.4, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.12.0 through 9.12.2, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.13.0 through 9.13.2, disable the "deny-answer-aliases" feature.

Exploit

Correção

DoS

Assertion Failure

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2022_2092
ALT-PU-2018-2141
BDU:2019-01628
BINDUDPDOS
CESA-2018_2570
CESA-2018_2571
CVE-2018-5740
DLA-1485-1
DLA-2807-1
ELSA-2018-2570
ELSA-2018-2571
MGASA-2018-0353
OPENSUSE-SU-2019:1533-1
OPENSUSE-SU-2019_1532-1
OPENSUSE-SU-2019_1533-1
RHSA-2018:2570
RHSA-2018:2571
RHSA-2018_2570
RHSA-2018_2571
SUSE-SU-2019:1407-1
SUSE-SU-2019:14074-1
SUSE-SU-2019:1449-1
SUSE-SU-2019:2502-1
SUSE-SU-2019_1407-1
SUSE-SU-2019_14074-1
SUSE-SU-2019_1449-1
SUSE-SU-2019_2502-1
USN-3769-1
USN-3769-2

Produtos afetados

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu