CVE-2018-5743
published 2019-10-09CVE-2018-5743: By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.40%
92.9th percentile
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.5.P4+dfsg-4 (bookworm) | bind9 1:9.11.5.P4+dfsg-4 (bookworm) |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 11.5.2 – 11.6.5 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_access_policy_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 11.5.2 – 11.6.5 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.5.2 – 11.6.5 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.1.1 | — |
| f5 | big-ip_analytics | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 11.5.2 – 11.6.5 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.1.1 | — |
| f5 | big-ip_application_acceleration_manager | 14.0.0 – 14.1.0 | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 11.5.2 – 11.6.5 | — |
| f5 | big-ip_application_security_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_application_security_manager | 13.0.0 – 13.1.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cr4-c5wq-3ccv: By design, BIND is intended to limit the number of TCP clients that can be connected at any given time
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2018-5743 [HIGH] CWE-770 GHSA-3cr4-c5wq-3ccv: By design, BIND is intended to limit the number of TCP clients that can be connected at any given time
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
OSV
CVE-2018-5743: By design, BIND is intended to limit the number of TCP clients that can be connected at any given time
osv·2019-10-09·CVSS 7.5
CVE-2018-5743 [HIGH] CVE-2018-5743: By design, BIND is intended to limit the number of TCP clients that can be connected at any given time
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
Red Hat
bind: TCP Pipelining doesn't limit TCP clients on a single connection
vendor_redhat·2019-11-20·CVSS 7.5
CVE-2019-6477 [HIGH] CWE-400 bind: TCP Pipelining doesn't limit TCP clients on a single connection
bind: TCP Pipelining doesn't limit TCP clients on a single connection
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
A flaw was found in the way bind limited the number of TCP clients that can be connected at any given time. A remote
Ubuntu
Bind vulnerability
vendor_ubuntu·2019-05-09
CVE-2018-5743 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to consume resources if it received specially crafted
network traffic.
USN-3956-1 fixed a vulnerability in Bind. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Bind incorrectly handled limiting the number of
simultaneous TCP clients. A remote attacker could possibly use this issue
to cause Bind to consume resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bind vulnerability
vendor_ubuntu·2019-04-25
CVE-2018-5743 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to consume resources if it received specially crafted
network traffic.
It was discovered that Bind incorrectly handled limiting the number of
simultaneous TCP clients. A remote attacker could possibly use this issue
to cause Bind to consume resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Limiting simultaneous TCP clients is ineffective
vendor_redhat·2019-04-24·CVSS 7.5
CVE-2018-5743 [HIGH] bind: Limiting simultaneous TCP clients is ineffective
bind: Limiting simultaneous TCP clients is ineffective
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability
Debian
CVE-2018-5743: bind9 - By design, BIND is intended to limit the number of TCP clients that can be conne...
vendor_debian·2018·CVSS 7.5
CVE-2018-5743 [HIGH] CVE-2018-5743: bind9 - By design, BIND is intended to limit the number of TCP clients that can be conne...
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
Scope: local
bookworm: resolved (fixe
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection
bugzilla·2019-11-18·CVSS 7.5
CVE-2019-6477 [HIGH] CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection
CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection
As per upstream advisory:
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The update to this functionality introduced by CVE-2018-5743 changed how BIND calculates the number of concurrent TCP clients from counting the outstanding TCP queries to counting the TCP client connections. On a server with TCP-pipelining capability, it is possible for one TCP client to send a large number of DNS requests over a single connection. Each outstanding query will be handled internally as an independent client request, thus bypassing the new TCP clients limit.
Discussion:
Acknowledgments:
Name: ISC
---
Created attachment 1637475
patch against 9.11.13
---
Plea
Bugzilla
CVE-2018-5743 bind: Limiting simultaneous TCP clients is ineffective [fedora-all]
bugzilla·2019-04-25·CVSS 7.5
CVE-2018-5743 [HIGH] CVE-2018-5743 bind: Limiting simultaneous TCP clients is ineffective [fedora-all]
CVE-2018-5743 bind: Limiting simultaneous TCP clients is ineffective [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2018-5743 bind99: bind: Limiting simultaneous TCP clients is ineffective [fedora-all]
bugzilla·2019-04-25·CVSS 7.5
CVE-2018-5743 [HIGH] CVE-2018-5743 bind99: bind: Limiting simultaneous TCP clients is ineffective [fedora-all]
CVE-2018-5743 bind99: bind: Limiting simultaneous TCP clients is ineffective [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2018-5743 bind: Limiting simultaneous TCP clients is ineffective
bugzilla·2019-04-24·CVSS 7.5
CVE-2018-5743 [HIGH] CVE-2018-5743 bind: Limiting simultaneous TCP clients is ineffective
CVE-2018-5743 bind: Limiting simultaneous TCP clients is ineffective
As per upstream advisory:
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contains an error which can be exploited to grow the number of simultaneous connections beyond this limit.
By exploiting the failure to limit simultaneous TCP connections,an attacker can deliberately exhaust the pool of file descriptors available to named, potentially affecting network connections and the management of files such as log files or zone journal files.
In cases wher
https://kb.isc.org/docs/cve-2018-5743https://support.f5.com/csp/article/K74009656?utm_source=f5support&%3Butm_medium=RSShttps://www.synology.com/security/advisory/Synology_SA_19_20https://kb.isc.org/docs/cve-2018-5743https://support.f5.com/csp/article/K74009656?utm_source=f5support&%3Butm_medium=RSShttps://www.synology.com/security/advisory/Synology_SA_19_20
2019-10-09
Published