CVE-2018-5744
published 2019-10-09CVE-2018-5744: A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.35%
87.4th percentile
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.5.P4+dfsg-1 (bookworm) | bind9 1:9.11.5.P4+dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | >= 9.10.7 < 9.10.8 | 9.10.8 |
| isc | bind | >= 9.11.3 < 9.11.5 | 9.11.5 |
| isc | bind | >= 9.12.0 < 9.12.3 | 9.12.3 |
| isc | bind | >= 9.13.0 < 9.13.6 | 9.13.6 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.19 | 1:9.9.5.dfsg-3ubuntu0.19 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.12 | 1:9.10.3.dfsg.P4-8ubuntu1.12 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.5 | 1:9.11.3+dfsg-1ubuntu1.5 |
| isc | bind_9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xcc7-r4h9-f7ph: A failure to free memory can occur when processing messages having a specific combination of EDNS options
ghsa_unreviewed·2022-05-24
CVE-2018-5744 [HIGH] CWE-772 GHSA-xcc7-r4h9-f7ph: A failure to free memory can occur when processing messages having a specific combination of EDNS options
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
OSV
CVE-2018-5744: A failure to free memory can occur when processing messages having a specific combination of EDNS options
osv·2019-10-09·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744: A failure to free memory can occur when processing messages having a specific combination of EDNS options
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
OSV
bind9 vulnerabilities
osv·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Toshifumi Sakaguchi discovered that Bind incorrectly handled memory. A
remote attacker could possibly use this issue to cause Bind to consume
resources, leading to a denial of service. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-5744)
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Toshifumi Sakaguchi discovered that Bind incorrectly handled memory. A
remote attacker could possibly use this issue to cause Bind to consume
resources, leading to a denial of service. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-5744)
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: A specially crafted packet can cause named to leak memory
vendor_redhat·2019-02-21·CVSS 7.5
CVE-2018-5744 [HIGH] CWE-400 bind: A specially crafted packet can cause named to leak memory
bind: A specially crafted packet can cause named to leak memory
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
A flaw was found in the way bind failed to free memory when processing certain messages. An attacker could use this flaw to cause a denial of service via memory exhaustion, by send specially crafted messages with Extension mechanisms for DNS (EDNS) options.
Statement: Versions of bind package shipped with Red Hat Enterprise Linux 5, 6, and 7 did not ship the vulnerable code and there
Debian
CVE-2018-5744: bind9 - A failure to free memory can occur when processing messages having a specific co...
vendor_debian·2018·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744: bind9 - A failure to free memory can occur when processing messages having a specific co...
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
Scope: local
bookworm: resolved (fixed in 1:9.11.5.P4+dfsg-1)
bullseye: resolved (fixed in 1:9.11.5.P4+dfsg-1)
forky: resolved (fixed in 1:9.11.5.P4+dfsg-1)
sid: resolved (fixed in 1:9.11.5.P4+dfsg-1)
trixie: resolved (fixed in 1:9.11.5.P4+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
bugzilla·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
bugzilla·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2018-5744 bind: A specially crafted packet can cause named to leak memory
bugzilla·2019-02-20·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 bind: A specially crafted packet can cause named to leak memory
CVE-2018-5744 bind: A specially crafted packet can cause named to leak memory
A flaw was found in Bind. A failure to free memory can occur when processing messages having a specific combination of EDNS options, causing named's memory use to grow without bounds until all memory is exhausted.
Discussion:
External References:
https://kb.isc.org/docs/cve-2018-5744
---
Created bind tracking bugs for this issue:
Affects: fedora-all [bug 1679925]
Created bind99 tracking bugs for this issue:
Affects: fedora-all [bug 1679926]
---
Ok, Fedora bugs are already prepared, it is public. Patches apply well to 9.11 bind in RHEL8. Where are bugs for RHEL?
---
Upstream advisory notes the following versions as being affected by this issue:
9.10.7 -> 9.10.8-P1
9.11.3 -> 9.11.5-P1
9.12.0 -> 9.12.
2019-10-09
Published