PT-2019-4564 · Isc+6 · Bind+6

Published

2018-08-14

·

Updated

2024-06-15

·

CVE-2019-6465

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BIND 9.9.0 through 9.10.8-P1 BIND 9.11.0 through 9.11.5-P2 BIND 9.12.0 through 9.12.3-P2 BIND 9.9.3-S1 through 9.11.5-S3 of BIND 9 Supported Preview Edition BIND 9.13.0 through 9.13.6
Description The issue is related to a problem with controls for zone transfers not being properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable. This allows an attacker to bypass the allow-transfer access control list (ACL) and receive a zone transfer of a DLZ, potentially gaining access to confidential data.
Recommendations For BIND 9.9.0 through 9.10.8-P1, update to a version outside of this range to resolve the issue. For BIND 9.11.0 through 9.11.5-P2, update to a version outside of this range to resolve the issue. For BIND 9.12.0 through 9.12.3-P2, update to a version outside of this range to resolve the issue. For BIND 9.9.3-S1 through 9.11.5-S3 of BIND 9 Supported Preview Edition, update to a version outside of this range to resolve the issue. For BIND 9.13.0 through 9.13.6, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to writable Dynamically Loadable Zones (DLZs) to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2141
ALT-PU-2019-1290
BDU:2020-00612
CESA-2019_3552
CESA-2020_1061
CVE-2019-6465
DLA-1697-1
DSA-4440-1
OPENSUSE-SU-2019:1533-1
OPENSUSE-SU-2019_1532-1
OPENSUSE-SU-2019_1533-1
OPENSUSE-SU-2024:10650-1
RHSA-2019:3552
RHSA-2019_3552
RHSA-2020:1061
RHSA-2020_1061
SUSE-SU-2019:1407-1
SUSE-SU-2019:14074-1
SUSE-SU-2019:1449-1
SUSE-SU-2019:2502-1
SUSE-SU-2019_1407-1
SUSE-SU-2019_14074-1
SUSE-SU-2019_1449-1
USN-3893-1
USN-3893-2

Affected Products

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu