CVE-2018-5738
published 2019-01-16CVE-2018-5738: Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted…
PriorityP349high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
11.07%
95.4th percentile
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of "allow-recursion {localhost; localnets;};" if "recursion yes;" is in effect and no values are explicitly set for "allow-query-cache" or "allow-query". However, because of the regression introduced by change #4777, it is possible when "recursion yes;" is in effect and no match list values are provided for "allow-query-cache" or "allow-query" for the setting of "allow-recursion" to inherit a setting of all hosts from the "allow-query" setting default, improperly permitting recursion to all clients. Affects BIND 9.9.12, 9.10.7, 9.11.3, 9.12.0->9.12.1-P2, the development release 9.13.0, and also releases 9.9.12-S1, 9.10.7-S1, 9.11.3-S1, and 9.11.3-S2 from BIND 9 Supported Preview Edition.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.11.3+dfsg-2 (bookworm) | bind9 1:9.11.3+dfsg-2 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-2 | 1:9.11.3+dfsg-2 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-2 | 1:9.11.3+dfsg-2 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-2 | 1:9.11.3+dfsg-2 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-2 | 1:9.11.3+dfsg-2 |
| isc | bind_9 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerability
vendor_ubuntu·2018-06-13
CVE-2018-5738 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could incorrectly enable recursion.
Andrew Skalski discovered that Bind could incorrectly enable recursion
when the "allow-recursion" setting wasn't specified. This issue could
improperly permit recursion to all clients, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Improper handling of configuration allows all clients to perform recursive queries
vendor_redhat·2018-06-12·CVSS 5.3
CVE-2018-5738 [MEDIUM] CWE-284 bind: Improper handling of configuration allows all clients to perform recursive queries
bind: Improper handling of configuration allows all clients to perform recursive queries
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intend
Debian
CVE-2018-5738: bind9 - Change #4777 (introduced in October 2017) introduced an unforeseen issue in rele...
vendor_debian·2018·CVSS 5.3
CVE-2018-5738 [MEDIUM] CVE-2018-5738: bind9 - Change #4777 (introduced in October 2017) introduced an unforeseen issue in rele...
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of "allow-recursion {localhost; localnets;};" if "recursion yes;" is in effect
GHSA
GHSA-cg2m-4gq8-j388: Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are pe
ghsa_unreviewed·2022-05-14
CVE-2018-5738 [HIGH] CWE-200 GHSA-cg2m-4gq8-j388: Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are pe
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of "allow-recursion {localhost; localnets;};" if "recursion yes;" is in effect
OSV
CVE-2018-5738: Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are pe
osv·2019-01-16·CVSS 7.5
CVE-2018-5738 [HIGH] CVE-2018-5738: Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are pe
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of "allow-recursion {localhost; localnets;};" if "recursion yes;" is in effect
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5738 bind99: bind: Improper handling of configuration allows all clients to perform recursive queries [fedora-all]
bugzilla·2018-06-13·CVSS 5.3
CVE-2018-5738 [MEDIUM] CVE-2018-5738 bind99: bind: Improper handling of configuration allows all clients to perform recursive queries [fedora-all]
CVE-2018-5738 bind99: bind: Improper handling of configuration allows all clients to perform recursive queries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2018-5738 bind: Improper handling of configuration allows all clients to perform recursive queries [fedora-all]
bugzilla·2018-06-13·CVSS 5.3
CVE-2018-5738 [MEDIUM] CVE-2018-5738 bind: Improper handling of configuration allows all clients to perform recursive queries [fedora-all]
CVE-2018-5738 bind: Improper handling of configuration allows all clients to perform recursive queries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2018-5738 bind: Improper handling of configuration allows all clients to perform recursive queries
bugzilla·2018-06-11·CVSS 5.3
CVE-2018-5738 [MEDIUM] CVE-2018-5738 bind: Improper handling of configuration allows all clients to perform recursive queries
CVE-2018-5738 bind: Improper handling of configuration allows all clients to perform recursive queries
BIND was found to not properly handle certain configuration options, unintentionally permiting all clients to perform recursive queries. This occurs when "recursion yes;" is in effect and no match list values are provided for "allow-query-cache" or "allow-query" for the setting of "allow-recursion" to inherit a setting of all hosts from the "allow-query" setting default.
The permitting of recursive queries to unauthorized clients can allow for:
* Increase the load on a server, possibly degrading service to authorized clients.
* A server to being co-opted for use in DNS reflection attacks.
* An attacker may be able to deduce which queries a server has previously serviced by examining the
http://www.securitytracker.com/id/1041115https://kb.isc.org/docs/aa-01616https://security.gentoo.org/glsa/201903-13https://security.netapp.com/advisory/ntap-20190830-0002/https://usn.ubuntu.com/3683-1/http://www.securitytracker.com/id/1041115https://kb.isc.org/docs/aa-01616https://security.gentoo.org/glsa/201903-13https://security.netapp.com/advisory/ntap-20190830-0002/https://usn.ubuntu.com/3683-1/
2019-01-16
Published