cbcvebase.
CVE-2018-5740
published 2019-01-16

CVE-2018-5740: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method…

PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
59.35%
99.0th percentile
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbind9< bind9 1:9.11.4.P1+dfsg-1 (bookworm)bind9 1:9.11.4.P1+dfsg-1 (bookworm)
debiandebian_linux
debiandebian_linux
iscbind>= 9.10.0 < 9.10.89.10.8
iscbind>= 9.11.0 < 9.11.49.11.4
iscbind>= 9.12.0 < 9.12.29.12.2
iscbind>= 9.13.0 < 9.13.29.13.2
iscbind>= 9.7.0 < 9.8.89.8.8
iscbind>= 9.9.0 < 9.9.139.9.13
iscbind9>= 0 < 1:9.11.4.P1+dfsg-11:9.11.4.P1+dfsg-1
iscbind9>= 0 < 1:9.11.4.P1+dfsg-11:9.11.4.P1+dfsg-1
iscbind9>= 0 < 1:9.11.4.P1+dfsg-11:9.11.4.P1+dfsg-1
iscbind9>= 0 < 1:9.11.4.P1+dfsg-11:9.11.4.P1+dfsg-1
iscbind_9
opensuseleap
opensuseleap
opensuseleap
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server

Detection & IOCsextracted from sources · hover to see the quote

  • Assertion failure in name.c triggered when 'deny-answer-aliases' feature is enabled and certain DNS records are processed; monitor named process for INSIST assertion crashes
  • Only BIND instances with 'deny-answer-aliases' explicitly enabled in configuration are exploitable; audit named.conf for this directive as a triage step
  • Exploitation causes an INSIST assertion failure leading to named process termination; monitor for unexpected named crashes or restarts as a detection signal
  • Affected BIND version ranges: 9.7.0–9.8.8, 9.9.0–9.9.13, 9.10.0–9.10.8, 9.11.0–9.11.4, 9.12.0–9.12.2, 9.13.0–9.13.2; inventory running named versions to identify exposure
  • ·'deny-answer-aliases' is not enabled in default BIND configurations; systems are only vulnerable if this option has been explicitly added to named.conf
  • ·Disabling 'deny-answer-aliases' in named.conf is a sufficient mitigation to prevent exploitation

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.