CVE-2018-5740
published 2019-01-16CVE-2018-5740: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method…
PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
59.35%
99.0th percentile
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.11.4.P1+dfsg-1 (bookworm) | bind9 1:9.11.4.P1+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| isc | bind | >= 9.10.0 < 9.10.8 | 9.10.8 |
| isc | bind | >= 9.11.0 < 9.11.4 | 9.11.4 |
| isc | bind | >= 9.12.0 < 9.12.2 | 9.12.2 |
| isc | bind | >= 9.13.0 < 9.13.2 | 9.13.2 |
| isc | bind | >= 9.7.0 < 9.8.8 | 9.8.8 |
| isc | bind | >= 9.9.0 < 9.9.13 | 9.9.13 |
| isc | bind9 | >= 0 < 1:9.11.4.P1+dfsg-1 | 1:9.11.4.P1+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.4.P1+dfsg-1 | 1:9.11.4.P1+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.4.P1+dfsg-1 | 1:9.11.4.P1+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.4.P1+dfsg-1 | 1:9.11.4.P1+dfsg-1 |
| isc | bind_9 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Assertion failure in name.c triggered when 'deny-answer-aliases' feature is enabled and certain DNS records are processed; monitor named process for INSIST assertion crashes ↗
- →Only BIND instances with 'deny-answer-aliases' explicitly enabled in configuration are exploitable; audit named.conf for this directive as a triage step ↗
- →Exploitation causes an INSIST assertion failure leading to named process termination; monitor for unexpected named crashes or restarts as a detection signal ↗
- →Affected BIND version ranges: 9.7.0–9.8.8, 9.9.0–9.9.13, 9.10.0–9.10.8, 9.11.0–9.11.4, 9.12.0–9.12.2, 9.13.0–9.13.2; inventory running named versions to identify exposure ↗
- ·'deny-answer-aliases' is not enabled in default BIND configurations; systems are only vulnerable if this option has been explicitly added to named.conf ↗
- ·Disabling 'deny-answer-aliases' in named.conf is a sufficient mitigation to prevent exploitation ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rqpc-6vjv-w22p: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potentia
ghsa_unreviewed·2022-05-13
CVE-2018-5740 [HIGH] CWE-617 GHSA-rqpc-6vjv-w22p: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potentia
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
OSV
CVE-2018-5740: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potentia
osv·2019-01-16·CVSS 7.5
CVE-2018-5740 [HIGH] CVE-2018-5740: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potentia
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
Ubuntu
Bind vulnerability
vendor_ubuntu·2018-10-01
CVE-2018-5740 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
USN-3769-1 fixed a vulnerability in Bind. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Bind incorrectly handled the deny-answer-aliases
feature. If this feature is enabled, a remote attacker could use this issue
to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bind vulnerability
vendor_ubuntu·2018-09-20
CVE-2018-5740 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled the deny-answer-aliases
feature. If this feature is enabled, a remote attacker could use this issue
to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service
vendor_redhat·2018-08-08·CVSS 7.5
CVE-2018-5740 [HIGH] CWE-617 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service
bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
A denial of service flaw was discovered in bind versions that include the "deny-answer-aliases" feature. This flaw may allow a remote attacker to trigger an INSIST assert in named leading to termination of the process and a
Debian
CVE-2018-5740: bind9 - "deny-answer-aliases" is a little-used feature intended to help recursive server...
vendor_debian·2018·CVSS 7.5
CVE-2018-5740 [HIGH] CVE-2018-5740: bind9 - "deny-answer-aliases" is a little-used feature intended to help recursive server...
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
Scope: local
bookworm: resolved (fixed in 1:9.11.4.P1+dfsg-1)
bullseye: resolved (fixed in 1:9.11.4.P1+dfsg-1)
forky: resolved (fixed in 1:9.11.4.P1+dfsg-1)
sid: resolved (fixed in 1:9.11.4.P1+dfsg-1)
trixie: resolved (fixed in 1:9.11.4.P1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5740 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service [fedora-all]
bugzilla·2018-08-08·CVSS 7.5
CVE-2018-5740 [HIGH] CVE-2018-5740 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service [fedora-all]
CVE-2018-5740 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2018-5740 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service
bugzilla·2018-08-08·CVSS 7.5
CVE-2018-5740 [HIGH] CVE-2018-5740 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service
CVE-2018-5740 bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service
BIND through versions 9.8.8, 9.9.13, 9.10.8, 9.11.4, 9.12.2 and 9.13.2 have a flaw in the "deny-answer-aliases" feature that can cause an INSIST assertion failure in named. A remote attacker could exploit this to cause named to crash.
Only servers which have explicitly enabled the "deny-answer-aliases" feature are at risk and disabling the feature prevents exploitation.
Discussion:
Acknowledgments:
Name: ISC
Upstream: Tony Finch (University of Cambridge)
---
Note that upstream notes version 9.7.0 as the first version affected by this flaw, as that's when deny-answer-aliases feature was added.
---
Mitigation:
Disabling the "deny-answer-aliases
Bugzilla
CVE-2018-5740 bind99: bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service [fedora-all]
bugzilla·2018-08-08·CVSS 7.5
CVE-2018-5740 [HIGH] CVE-2018-5740 bind99: bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service [fedora-all]
CVE-2018-5740 bind99: bind: processing of certain records when "deny-answer-aliases" is in use may trigger an assert leading to a denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00027.htmlhttp://www.securityfocus.com/bid/105055http://www.securitytracker.com/id/1041436https://access.redhat.com/errata/RHSA-2018:2570https://access.redhat.com/errata/RHSA-2018:2571https://kb.isc.org/docs/aa-01639https://lists.debian.org/debian-lts-announce/2018/08/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2021/11/msg00001.htmlhttps://security.gentoo.org/glsa/201903-13https://security.netapp.com/advisory/ntap-20180926-0003/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03927en_ushttps://usn.ubuntu.com/3769-1/https://usn.ubuntu.com/3769-2/http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00027.htmlhttp://www.securityfocus.com/bid/105055http://www.securitytracker.com/id/1041436https://access.redhat.com/errata/RHSA-2018:2570https://access.redhat.com/errata/RHSA-2018:2571https://kb.isc.org/docs/aa-01639https://lists.debian.org/debian-lts-announce/2018/08/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2021/11/msg00001.htmlhttps://security.gentoo.org/glsa/201903-13https://security.netapp.com/advisory/ntap-20180926-0003/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03927en_ushttps://usn.ubuntu.com/3769-1/https://usn.ubuntu.com/3769-2/
2019-01-16
Published