CVE-2018-5741Incorrect Authorization in Bind

Severity
6.5MEDIUMNVD
EPSS
1.0%
top 23.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16
Latest updateMay 13

Description

To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. Unfortunately, some rule types were not initially documented, and when documentation for them was added to the Administrator Reference Manual (ARM) in change #3112, the language that was adde

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDisc/bind9.12.09.12.3+1
Debianisc/bind9< 1:9.11.5+dfsg-1+3
CVEListV5isc/bind_9BIND 9 Versions prior to BIND 9.11.5 and BIND 9.12.3

🔴Vulnerability Details

3
GHSA
GHSA-ghpp-72v8-mpmv: To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-polic2022-05-13
CVEList
Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentation2019-01-16
OSV
CVE-2018-5741: To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-polic2019-01-16

📋Vendor Advisories

2
Red Hat
bind: Incorrect documentation of krb5-subdomain and ms-subdomain update policies2018-09-20
Debian
CVE-2018-5741: bind9 - To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to u...2018

💬Community

3
Bugzilla
CVE-2018-5741 bind99: bind: Incorrect documentation of krb5-subdomain and ms-subdomain update policies [fedora-all]2018-09-20
Bugzilla
CVE-2018-5741 bind: Incorrect documentation of krb5-subdomain and ms-subdomain update policies [fedora-all]2018-09-20
Bugzilla
CVE-2018-5741 bind: Incorrect documentation of krb5-subdomain and ms-subdomain update policies2018-09-20
CVE-2018-5741 — Incorrect Authorization in ISC Bind | cvebase