PT-2019-4853 · Isc+6 · Bind+6

Publicado

2019-06-19

·

Atualizado

2024-06-15

·

CVE-2019-6471

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions 9.11.0 through 9.11.7 BIND versions 9.12.0 through 9.12.4-P1 BIND versions 9.14.0 through 9.14.2 BIND 9.13 development branch (all releases) BIND 9.15 development branch version 9.15.0 BIND Supported Preview Edition versions 9.11.3-S1 through 9.11.7-S1
Description A race condition may occur when discarding malformed packets, resulting in BIND exiting due to a REQUIRE assertion failure in dispatch.c. This issue can lead to a denial of service, allowing a remote attacker to cause the service to terminate. The vulnerability is related to the handling of incoming packets and can be triggered by specially crafted packets.
Recommendations For BIND versions 9.11.0 through 9.11.7, update to version 9.11.9 or later. For BIND versions 9.12.0 through 9.12.4-P1, update to a version later than 9.12.4-P1. For BIND versions 9.14.0 through 9.14.2, update to version 9.14.4 or later. For the BIND 9.13 development branch, update to a version that includes the fix for this issue. For the BIND 9.15 development branch, update to version 9.15.2 or later. For BIND Supported Preview Edition versions 9.11.3-S1 through 9.11.7-S1, update to a version later than 9.11.7-S1.

Correção

DoS

Race Condition

Assertion Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2101
ALT-PU-2019-3186
BDU:2020-01437
CESA-2019_1714
CVE-2019-6471
MGASA-2019-0299
OPENSUSE-SU-2019:2263-1
OPENSUSE-SU-2019:2265-1
OPENSUSE-SU-2019_2263-1
OPENSUSE-SU-2019_2265-1
OPENSUSE-SU-2024:10650-1
RHSA-2019:1714
RHSA-2019_1714
SUSE-SU-2019:2502-1
SUSE-SU-2019:2550-1
SUSE-SU-2019_2550-1
USN-4026-1

Produtos afetados

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu