Vulnerability Name:

CVE-2018-5744 (CCN-157371)

Assigned:2018-01-17
Published:2019-02-21
Updated:2019-11-05
Summary:A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-772
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-5744

Source: XF
Type: UNKNOWN
isc-bind-cve20185744-dos(157371)

Source: CCN
Type: ISC Web site
CVE-2018-5744: A specially crafted packet can cause named to leak memory

Source: CONFIRM
Type: Vendor Advisory
https://kb.isc.org/docs/cve-2018-5744

Source: CCN
Type: IBM Security Bulletin 876698 (i)
IBM i is affected by networking BIND vulnerabilities CVE-2018-5744 CVE-2019-6465 and CVE-2018-5745.

Source: CCN
Type: IBM Security Bulletin 6361639 (Integrated Analytics System)
Vulnerability in BIND affects IBM Integrated Analytics System

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-5744

Vulnerable Configuration:Configuration 1:
  • cpe:/a:isc:bind:*:*:*:*:*:*:*:* (Version >= 9.10.7 and < 9.10.8)
  • OR cpe:/a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*
  • OR cpe:/a:isc:bind:9.10.8:-:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.10.8:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.10.8:rc1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.10.8:rc2:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:*:*:*:*:*:*:*:* (Version >= 9.11.3 and < 9.11.5)
  • OR cpe:/a:isc:bind:9.11.5:-:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.11.5:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.11.5:rc1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*
  • OR cpe:/a:isc:bind:*:*:*:*:*:*:*:* (Version >= 9.12.0 and < 9.12.3)
  • OR cpe:/a:isc:bind:9.12.3:-:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.12.3:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.12.3:rc1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:*:*:*:*:*:*:*:* (Version >= 9.13.0 and < 9.13.6)

  • Configuration CCN 1:
  • cpe:/a:isc:bind:9.10.7:*:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.11.3:*:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.12.0:*:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.13.0:*:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.10.8:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.11.5:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.12.3:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.10.7:s1:*:*:*:*:*:*
  • OR cpe:/a:isc:bind:9.11.5:s3:*:*:*:*:*:*
  • AND
  • cpe:/o:ibm:i:7.17.27.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7450
    P
    bind-utils-9.16.38-150400.5.20.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7449
    P
    bind-devel-9.16.6-150300.22.27.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3469
    P
    davfs2-1.5.2-2.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2876
    P
    bind-devel-9.16.6-150300.22.16.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94507
    P
    bind-utils-9.16.20-150400.3.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2877
    P
    bind-utils-9.16.20-150400.3.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95099
    P
    bind-9.16.20-150400.3.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94506
    P
    bind-devel-9.16.6-150300.22.16.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:16
    P
    bind-devel-9.16.6-20.39 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:945
    P
    Security update for net-snmp (Important)
    2022-01-11
    oval:org.opensuse.security:def:63320
    P
    bind-9.16.6-20.39 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2231
    P
    bind-9.16.6-20.39 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100792
    P
    bind-devel-9.16.6-20.39 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71775
    P
    bind-devel-9.16.6-20.39 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62034
    P
    bind-devel-9.16.6-20.39 on GA media (Moderate)
    2021-08-09
    oval:com.ubuntu.bionic:def:201857440000000
    V
    CVE-2018-5744 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-10-09
    oval:com.ubuntu.bionic:def:20185744000
    V
    CVE-2018-5744 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-02-21
    oval:com.ubuntu.cosmic:def:201857440000000
    V
    CVE-2018-5744 on Ubuntu 18.10 (cosmic) - medium.
    2019-02-21
    oval:com.ubuntu.cosmic:def:20185744000
    V
    CVE-2018-5744 on Ubuntu 18.10 (cosmic) - medium.
    2019-02-21
    oval:com.ubuntu.trusty:def:20185744000
    V
    CVE-2018-5744 on Ubuntu 14.04 LTS (trusty) - medium.
    2019-02-21
    oval:com.ubuntu.xenial:def:201857440000000
    V
    CVE-2018-5744 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-02-21
    oval:com.ubuntu.xenial:def:20185744000
    V
    CVE-2018-5744 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-02-21
    BACK
    isc bind *
    isc bind 9.10.7 s1
    isc bind 9.10.8 -
    isc bind 9.10.8 p1
    isc bind 9.10.8 rc1
    isc bind 9.10.8 rc2
    isc bind *
    isc bind 9.11.5 -
    isc bind 9.11.5 p1
    isc bind 9.11.5 rc1
    isc bind 9.11.5 s3
    isc bind *
    isc bind 9.12.3 -
    isc bind 9.12.3 p1
    isc bind 9.12.3 rc1
    isc bind *
    isc bind 9.10.7
    isc bind 9.11.3
    isc bind 9.12.0
    isc bind 9.13.0
    isc bind 9.10.8 p1
    isc bind 9.11.5 p1
    isc bind 9.12.3 p1
    isc bind 9.10.7 s1
    isc bind 9.11.5 s3
    ibm i 7.17.27.3