CVE-2018-5742
published 2019-10-30CVE-2018-5742: While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.57%
73.8th percentile
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | 9.9.4-65 – 9.9.4-72 | — |
| redhat | bind9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r4vj-82q4-crg5: While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer
ghsa_unreviewed·2022-05-24
CVE-2018-5742 [MEDIUM] GHSA-r4vj-82q4-crg5: While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected.
Red Hat
bind: Crash from assertion error when debug log level is 10 and log entries meet buffer boundary
vendor_redhat·2018-12-18·CVSS 7.5
CVE-2018-5742 [HIGH] CWE-400 bind: Crash from assertion error when debug log level is 10 and log entries meet buffer boundary
bind: Crash from assertion error when debug log level is 10 and log entries meet buffer boundary
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected.
Statement: This flaw appears to be exploitable only when debug logging is enabled and set to at least a level of 10. As this configuration should be rare in production instances of bind, it is unlikely that most servers will be exploitable. The debug level of the bind server can be checked via the rndc status command, which will return the current trace level as "debug level". A value of
Debian
CVE-2018-5742: bind9 - While backporting a feature for a newer branch of BIND9, RedHat introduced a pat...
vendor_debian·2018·CVSS 7.5
CVE-2018-5742 [HIGH] CVE-2018-5742: bind9 - While backporting a feature for a newer branch of BIND9, RedHat introduced a pat...
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2019-10-30
Published