PT-2018-2730 · Isc+6 · Bind+6

Published

2016-09-28

·

Updated

2022-05-10

·

CVE-2018-5740

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.7.0 through 9.8.8 BIND versions 9.9.0 through 9.9.13 BIND versions 9.10.0 through 9.10.8 BIND versions 9.11.0 through 9.11.4 BIND versions 9.12.0 through 9.12.2 BIND versions 9.13.0 through 9.13.2
Description The issue is related to the "deny-answer-aliases" feature in the BIND DNS server, which is intended to protect against DNS rebinding attacks. However, a defect in this feature can cause an assertion failure in name.c, leading to a denial of service. This can be exploited by a remote attacker. The feature is little-used and only servers with the feature explicitly enabled are at risk.
Recommendations To resolve the issue for BIND versions 9.7.0 through 9.8.8, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.9.0 through 9.9.13, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.10.0 through 9.10.8, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.11.0 through 9.11.4, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.12.0 through 9.12.2, disable the "deny-answer-aliases" feature. To resolve the issue for BIND versions 9.13.0 through 9.13.2, disable the "deny-answer-aliases" feature.

Exploit

Fix

DoS

Assertion Failure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022_2092
ALT-PU-2018-2141
BDU:2019-01628
BINDUDPDOS
CESA-2018_2570
CESA-2018_2571
CVE-2018-5740
DLA-1485-1
DLA-2807-1
ELSA-2018-2570
ELSA-2018-2571
MGASA-2018-0353
OPENSUSE-SU-2019:1533-1
OPENSUSE-SU-2019_1532-1
OPENSUSE-SU-2019_1533-1
RHSA-2018:2570
RHSA-2018:2571
RHSA-2018_2570
RHSA-2018_2571
SUSE-SU-2019:1407-1
SUSE-SU-2019:14074-1
SUSE-SU-2019:1449-1
SUSE-SU-2019:2502-1
SUSE-SU-2019_1407-1
SUSE-SU-2019_14074-1
SUSE-SU-2019_1449-1
SUSE-SU-2019_2502-1
USN-3769-1
USN-3769-2

Affected Products

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu