PT-2019-5190 · Isc+5 · Bind+6

Giorgos Skafidas

·

Published

2018-07-14

·

Updated

2026-01-30

·

CVE-2019-6470

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dhcpd versions prior to 4.4.1 when using BIND versions 9.11.2 or later
Description The issue is related to bugs in the ISC BIND libraries used by dhcpd when operating in DHCPv6 mode, and a bug in dhcpd itself. The bugs can cause a crash, potentially leading to a denial of service. The crash probability is reported to be large, although it is unclear if this can be manipulated by an attacker. The problem arises when dhcpd is used with specific versions of BIND, particularly those with versions 9.11.2 or later, or versions with specific bug fixes backported to them.
Recommendations For dhcpd versions prior to 4.4.1, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of dhcpd in DHCPv6 mode until a patch is available. Operators are advised to consult their vendor documentation for specific guidance on updating or mitigating the vulnerability in their particular build of dhcpd.

Exploit

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-34558
AZL-6326
BDU:2020-01863
CESA-2019_2060
CESA-2019_3525
CVE-2019-6470
OPENSUSE-SU-2019:2340-1
OPENSUSE-SU-2019:2341-1
OPENSUSE-SU-2019_2340-1
OPENSUSE-SU-2019_2341-1
OPENSUSE-SU-2024:10715-1
RHSA-2019:2060
RHSA-2019:3525
RHSA-2019_2060
RHSA-2019_3525
SUSE-SU-2019:2657-1
SUSE-SU-2019:2727-1
SUSE-SU-2019:2727-2
SUSE-SU-2019_2657-1
SUSE-SU-2019_2727-1
SUSE-SU-2019_2727-2
USN-3973-1

Affected Products

Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu
Dhcpd