PT-2019-4564 · Isc+6 · Bind+6

Publicado

2018-08-14

·

Atualizado

2024-06-15

·

CVE-2019-6465

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BIND 9.9.0 through 9.10.8-P1 BIND 9.11.0 through 9.11.5-P2 BIND 9.12.0 through 9.12.3-P2 BIND 9.9.3-S1 through 9.11.5-S3 of BIND 9 Supported Preview Edition BIND 9.13.0 through 9.13.6
Description The issue is related to a problem with controls for zone transfers not being properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable. This allows an attacker to bypass the allow-transfer access control list (ACL) and receive a zone transfer of a DLZ, potentially gaining access to confidential data.
Recommendations For BIND 9.9.0 through 9.10.8-P1, update to a version outside of this range to resolve the issue. For BIND 9.11.0 through 9.11.5-P2, update to a version outside of this range to resolve the issue. For BIND 9.12.0 through 9.12.3-P2, update to a version outside of this range to resolve the issue. For BIND 9.9.3-S1 through 9.11.5-S3 of BIND 9 Supported Preview Edition, update to a version outside of this range to resolve the issue. For BIND 9.13.0 through 9.13.6, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to writable Dynamically Loadable Zones (DLZs) to minimize the risk of exploitation.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2141
ALT-PU-2019-1290
BDU:2020-00612
CESA-2019_3552
CESA-2020_1061
CVE-2019-6465
DLA-1697-1
DSA-4440-1
OPENSUSE-SU-2019:1533-1
OPENSUSE-SU-2019_1532-1
OPENSUSE-SU-2019_1533-1
OPENSUSE-SU-2024:10650-1
RHSA-2019:3552
RHSA-2019_3552
RHSA-2020:1061
RHSA-2020_1061
SUSE-SU-2019:1407-1
SUSE-SU-2019:14074-1
SUSE-SU-2019:1449-1
SUSE-SU-2019:2502-1
SUSE-SU-2019_1407-1
SUSE-SU-2019_14074-1
SUSE-SU-2019_1449-1
USN-3893-1
USN-3893-2

Produtos afetados

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu