PT-2018-2730 · Isc+6 · Bind+6
Publicado
2016-09-28
·
Atualizado
2022-05-10
·
CVE-2018-5740
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BIND versions 9.7.0 through 9.8.8
BIND versions 9.9.0 through 9.9.13
BIND versions 9.10.0 through 9.10.8
BIND versions 9.11.0 through 9.11.4
BIND versions 9.12.0 through 9.12.2
BIND versions 9.13.0 through 9.13.2
Description
The issue is related to the "deny-answer-aliases" feature in the BIND DNS server, which is intended to protect against DNS rebinding attacks. However, a defect in this feature can cause an assertion failure in name.c, leading to a denial of service. This can be exploited by a remote attacker. The feature is little-used and only servers with the feature explicitly enabled are at risk.
Recommendations
To resolve the issue for BIND versions 9.7.0 through 9.8.8, disable the "deny-answer-aliases" feature.
To resolve the issue for BIND versions 9.9.0 through 9.9.13, disable the "deny-answer-aliases" feature.
To resolve the issue for BIND versions 9.10.0 through 9.10.8, disable the "deny-answer-aliases" feature.
To resolve the issue for BIND versions 9.11.0 through 9.11.4, disable the "deny-answer-aliases" feature.
To resolve the issue for BIND versions 9.12.0 through 9.12.2, disable the "deny-answer-aliases" feature.
To resolve the issue for BIND versions 9.13.0 through 9.13.2, disable the "deny-answer-aliases" feature.
Exploit
Correção
DoS
Assertion Failure
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu