Vulnerability Name: | CVE-2018-5734 (CCN-139615) | ||||||||||||||||||||
Assigned: | 2018-02-28 | ||||||||||||||||||||
Published: | 2018-02-28 | ||||||||||||||||||||
Updated: | 2019-10-09 | ||||||||||||||||||||
Summary: | While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2. | ||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-617 | ||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-5734 Source: BID Type: Third Party Advisory, VDB Entry 103189 Source: CCN Type: BID-103189 ISC BIND CVE-2018-5734 Remote Denial of Service Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1040438 Source: XF Type: UNKNOWN isc-bind-cve20185734-dos(139615) Source: CCN Type: ISC Security Advisory AA-01562 CVE-2018-5734: A malformed request can trigger an assertion failure in badcache.c Source: CONFIRM Type: Vendor Advisory https://kb.isc.org/docs/aa-01562 Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20180926-0005/ | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |