PT-2019-4818 · Isc+6 · Bind+6

Published

2019-04-24

·

Updated

2024-06-15

·

CVE-2018-5743

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.9.0 through 9.10.8-P1 BIND versions 9.11.0 through 9.11.6 BIND versions 9.12.0 through 9.12.4 BIND version 9.14.0 BIND 9 Supported Preview Edition versions 9.9.3-S1 through 9.11.5-S3 BIND 9 Supported Preview Edition version 9.11.5-S5 BIND versions 9.13.0 through 9.13.7
Description The issue is related to the failure to limit the number of simultaneous TCP connections, which can be exploited to cause a denial of service. This can lead to exhaustion of the pool of file descriptors available to named. The vulnerability is also associated with unlimited resource allocation in the managed-keys function of the DNS server.
Recommendations For BIND versions 9.9.0 through 9.10.8-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.11.0 through 9.11.6, update to a version outside of this range to mitigate the risk. For BIND versions 9.12.0 through 9.12.4, update to a version outside of this range to mitigate the risk. For BIND version 9.14.0, update to a version outside of this range to mitigate the risk. For BIND 9 Supported Preview Edition versions 9.9.3-S1 through 9.11.5-S3, update to a version outside of this range to mitigate the risk. For BIND 9 Supported Preview Edition version 9.11.5-S5, update to a version outside of this range to mitigate the risk. For BIND versions 9.13.0 through 9.13.7, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the number of simultaneous TCP connections to prevent exhaustion of file descriptors.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1739
BDU:2020-01402
CESA-2019_1145
CESA-2019_1294
CESA-2019_1492
CVE-2018-5743
DLA-1859-1
DSA-4440-1
MGASA-2019-0299
OPENSUSE-SU-2019:1533-1
OPENSUSE-SU-2019_1532-1
OPENSUSE-SU-2019_1533-1
OPENSUSE-SU-2024:10650-1
RHSA-2019:1145
RHSA-2019:1294
RHSA-2019:1492
RHSA-2019:2698
RHSA-2019:2977
RHSA-2019_1145
RHSA-2019_1294
RHSA-2019_1492
SUSE-SU-2019:1407-1
SUSE-SU-2019:14074-1
SUSE-SU-2019:1449-1
SUSE-SU-2019:2502-1
SUSE-SU-2019_1407-1
SUSE-SU-2019_14074-1
SUSE-SU-2019_1449-1
USN-3956-1
USN-3956-2

Affected Products

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu