PT-2019-4629 · Isc+6 · Bind+6

Published

2018-08-14

·

Updated

2024-06-15

·

CVE-2018-5745

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.9.0 through 9.10.8-P1 BIND versions 9.11.0 through 9.11.5-P1 BIND versions 9.12.0 through 9.12.3-P1 BIND 9 Supported Preview Edition versions 9.9.3-S1 through 9.11.5-S3 BIND versions 9.13.0 through 9.13.6
Description The issue is related to an error in the managed-keys feature of the BIND server, which can cause the server to exit due to an assertion failure when a trust anchor's keys are replaced with keys using an unsupported algorithm during key rollover. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For BIND versions 9.9.0 through 9.10.8-P1, update to a version that fixes the issue. For BIND versions 9.11.0 through 9.11.5-P1, update to a version that fixes the issue. For BIND versions 9.12.0 through 9.12.3-P1, update to a version that fixes the issue. For BIND 9 Supported Preview Edition versions 9.9.3-S1 through 9.11.5-S3, update to a version that fixes the issue. For BIND versions 9.13.0 through 9.13.6, update to a version that fixes the issue. As a temporary workaround, consider disabling the managed-keys feature until a patch is available.

Exploit

Fix

Allocation of Resources Without Limits

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2141
ALT-PU-2019-1290
BDU:2020-00773
BDU:2020-01402
CESA-2019_3552
CESA-2020_1061
CVE-2018-5745
DLA-1697-1
DSA-4440-1
OPENSUSE-SU-2019:1533-1
OPENSUSE-SU-2019_1532-1
OPENSUSE-SU-2019_1533-1
OPENSUSE-SU-2024:10650-1
RHSA-2019:3552
RHSA-2019_3552
RHSA-2020:1061
RHSA-2020_1061
SUSE-SU-2019:1407-1
SUSE-SU-2019:14074-1
SUSE-SU-2019:1449-1
SUSE-SU-2019:2502-1
SUSE-SU-2019_1407-1
SUSE-SU-2019_14074-1
SUSE-SU-2019_1449-1
USN-3893-1
USN-3893-2

Affected Products

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu