PT-2019-5505 · Isc+1 · Bind+1

Published

2019-04-24

·

Updated

2019-12-18

·

CVE-2019-6467

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions 9.12.0 through 9.12.4 BIND version 9.14.0 BIND 9.13 development branch
Description A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c. This issue is most likely to occur when the server is performing NXDOMAIN redirection for recursive clients and also serving a local copy of the root zone or using mirroring to provide the root zone. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For BIND versions 9.12.0 through 9.12.4, consider disabling the nxdomain-redirect feature until a patch is available. For BIND version 9.14.0, consider disabling the nxdomain-redirect feature until a patch is available. For the BIND 9.13 development branch, consider disabling the nxdomain-redirect feature until a patch is available. As a temporary workaround, consider restricting the use of the query.c function to minimize the risk of exploitation.

Exploit

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03322
CVE-2019-6467

Affected Products

Bind
Bind Server