CVE-2018-5736
published 2019-01-16CVE-2018-5736: An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several…
PriorityP340medium5.3CVSS 3.0
AVNACHPRLUINSUCNINAH
EPSS
18.02%
97.0th percentile
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
| isc | bind | >= 0 < 9.12.1_p2-r0 | 9.12.1_p2-r0 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6p6q-g6w7-h5f9: An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts severa
ghsa_unreviewed·2022-05-13
CVE-2018-5736 [MEDIUM] GHSA-6p6q-g6w7-h5f9: An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts severa
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
OSV
CVE-2018-5736: An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts severa
osv·2019-01-16·CVSS 5.3
CVE-2018-5736 [MEDIUM] CVE-2018-5736: An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts severa
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
Red Hat
bind: Multiple transfers of a zone in quick succession can cause an assertion failure in rbtdb.c
vendor_redhat·2018-05-18·CVSS 5.3
CVE-2018-5736 [MEDIUM] CWE-400 bind: Multiple transfers of a zone in quick succession can cause an assertion failure in rbtdb.c
bind: Multiple transfers of a zone in quick succession can cause an assertion failure in rbtdb.c
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
A flaw was found in the way zone databases were handled by bind. An attacker with permissions to initiate a zone transfer could cause bind to crash.
Statement: This security flaw only affects bind versions 9.12.0 and 9.1
Debian
CVE-2018-5736: bind9 - An error in zone database reference counting can lead to an assertion failure if...
vendor_debian·2018·CVSS 5.3
CVE-2018-5736 [MEDIUM] CVE-2018-5736: bind9 - An error in zone database reference counting can lead to an assertion failure if...
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104386http://www.securitytracker.com/id/1040941https://kb.isc.org/docs/aa-01602https://security.netapp.com/advisory/ntap-20180926-0004/http://www.securityfocus.com/bid/104386http://www.securitytracker.com/id/1040941https://kb.isc.org/docs/aa-01602https://security.netapp.com/advisory/ntap-20180926-0004/
2019-01-16
Published