PT-2022-4535 · Isc+3 · Bind+3

Published

2022-05-18

·

Updated

2024-06-15

·

CVE-2022-1183

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.18.0 through 9.18.2 BIND version 9.19.0
Description The issue is related to the use of the assert() function or similar operators in the named daemon of the DNS server BIND. Exploitation of this issue may allow a remote attacker to cause a denial of service. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. The issue affects configurations using DNS over HTTPS (DoH), but not those using DNS over TLS (DoT) alone.
Recommendations For BIND versions 9.18.0 through 9.18.2, update to version 9.18.3 or later. For BIND version 9.19.0, update to version 9.19.1 or later. As a temporary workaround, consider disabling the http reference in the listen-on statements in named.conf to minimize the risk of exploitation. Restrict access to the vulnerable named daemon to minimize the risk of exploitation. Avoid using the http protocol in the listen-on statements until the issue is resolved.

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05404
CVE-2022-1183
OPENSUSE-SU-2024:12129-1
USN-5429-1

Affected Products

Bind
Bind Server
Linuxmint
Ubuntu