CVE-2018-5745
published 2019-10-09CVE-2018-5745: "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
2.28%
81.3th percentile
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.5.P4+dfsg-1 (bookworm) | bind9 1:9.11.5.P4+dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.11.0 – 9.11.4 | — |
| isc | bind | 9.12.0 – 9.12.2 | — |
| isc | bind | 9.13.0 – 9.13.6 | — |
| isc | bind | 9.9.0 – 9.10.7 | — |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.19 | 1:9.9.5.dfsg-3ubuntu0.19 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.12 | 1:9.10.3.dfsg.P4-8ubuntu1.12 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.5 | 1:9.11.3+dfsg-1ubuntu1.5 |
| isc | bind_9 | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5r3-98fj-vgcv: "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in
ghsa_unreviewed·2022-05-24·CVSS 4.9
CVE-2018-5745 [MEDIUM] CWE-327 GHSA-p5r3-98fj-vgcv: "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
OSV
CVE-2018-5745: "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in
osv·2019-10-09·CVSS 4.9
CVE-2018-5745 [MEDIUM] CVE-2018-5745: "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
OSV
bind9 vulnerabilities
osv·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Toshifumi Sakaguchi discovered that Bind incorrectly handled memory. A
remote attacker could possibly use this issue to cause Bind to consume
resources, leading to a denial of service. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-5744)
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2019-02-25·CVSS 4.9
CVE-2018-5745 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
USN-3893-1 fixed a vulnerability in Bind. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Toshifumi Sakaguchi discovered that Bind incorrectly handled memory. A
remote attacker could possibly use this issue to cause Bind to consume
resources, leading to a denial of service. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-5744)
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: An assertion failure if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
vendor_redhat·2019-02-21·CVSS 4.9
CVE-2018-5745 [MEDIUM] CWE-617 bind: An assertion failure if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
bind: An assertion failure if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not be
Debian
CVE-2018-5745: bind9 - "managed-keys" is a feature which allows a BIND resolver to automatically mainta...
vendor_debian·2018·CVSS 4.9
CVE-2018-5745 [MEDIUM] CVE-2018-5745: bind9 - "managed-keys" is a feature which allows a BIND resolver to automatically mainta...
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
Scope: local
bookworm: resolved (fixed in 1:9.11.5.P4+dfsg-1)
bu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
bugzilla·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
bugzilla·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2018-5745 bind: An assertion failure if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
bugzilla·2019-02-20·CVSS 4.9
CVE-2018-5745 [MEDIUM] CVE-2018-5745 bind: An assertion failure if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
CVE-2018-5745 bind: An assertion failure if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
A flaw was found in Bind. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure causing denial of service.
Discussion:
External References:
https://kb.isc.org/docs/cve-2018-5745
---
Created bind tracking bugs for this issue:
Affects: fedora-all [bug 1679925]
Created bind99 tracking bugs for this issue:
Affects: fedora-all [bug 1679926]
---
Upstream advisory notes the following versions as being affected by this issue:
9.9.0 -> 9.10.8-P1
9.11.0 -> 9.11.5-P1
9.12.0 -> 9.12.3-P1
9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition
9.13.0 -> 9.13.6 of the 9.13 developmen
2019-10-09
Published