CVE-2019-6465
published 2019-10-09CVE-2019-6465: Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 ->…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
3.73%
88.7th percentile
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.5.P4+dfsg-1 (bookworm) | bind9 1:9.11.5.P4+dfsg-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.11.0 – 9.11.4 | — |
| isc | bind | 9.12.0 – 9.12.2 | — |
| isc | bind | 9.13.0 – 9.13.6 | — |
| isc | bind | 9.9.0 – 9.10.7 | — |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.5.P4+dfsg-1 | 1:9.11.5.P4+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.19 | 1:9.9.5.dfsg-3ubuntu0.19 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.12 | 1:9.10.3.dfsg.P4-8ubuntu1.12 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.5 | 1:9.11.3+dfsg-1ubuntu1.5 |
| isc | bind_9 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5hgv-gr6q-xvqx: Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9
ghsa_unreviewed·2022-05-24·CVSS 5.3
CVE-2019-6465 [MEDIUM] CWE-732 GHSA-5hgv-gr6q-xvqx: Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.
OSV
CVE-2019-6465: Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9
osv·2019-10-09·CVSS 5.3
CVE-2019-6465 [MEDIUM] CVE-2019-6465: Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.
OSV
bind9 vulnerabilities
osv·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Toshifumi Sakaguchi discovered that Bind incorrectly handled memory. A
remote attacker could possibly use this issue to cause Bind to consume
resources, leading to a denial of service. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-5744)
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2019-02-25·CVSS 4.9
CVE-2018-5745 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
USN-3893-1 fixed a vulnerability in Bind. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Toshifumi Sakaguchi discovered that Bind incorrectly handled memory. A
remote attacker could possibly use this issue to cause Bind to consume
resources, leading to a denial of service. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-5744)
It was discovered that Bind incorrectly handled certain trust anchors when
used with the "managed-keys" feature. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service.
(CVE-2018-5745)
It was discovered that Bind incorrectly handled certain controls for zone
transfers, contrary to expectations. (CVE-2019-6465)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Controls for zone transfers may not be properly applied to DLZs if the zones are writable
vendor_redhat·2019-02-21·CVSS 5.3
CVE-2019-6465 [MEDIUM] CWE-284 bind: Controls for zone transfers may not be properly applied to DLZs if the zones are writable
bind: Controls for zone transfers may not be properly applied to DLZs if the zones are writable
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.
It was found that the controls for zone transfer were not properly applied to Dynamically Loadable Zones (DLZs). An attacker acting as a DNS client could use this flaw to request and receive a zone transfer of a DLZ even when not permitted to do so by the "all
Debian
CVE-2019-6465: bind9 - Controls for zone transfers may not be properly applied to Dynamically Loadable ...
vendor_debian·2019·CVSS 5.3
CVE-2019-6465 [MEDIUM] CVE-2019-6465: bind9 - Controls for zone transfers may not be properly applied to Dynamically Loadable ...
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.
Scope: local
bookworm: resolved (fixed in 1:9.11.5.P4+dfsg-1)
bullseye: resolved (fixed in 1:9.11.5.P4+dfsg-1)
forky: resolved (fixed in 1:9.11.5.P4+dfsg-1)
sid: resolved (fixed in 1:9.11.5.P4+dfsg-1)
trixie: resolved (fixed in 1:9.11.5.P4+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
bugzilla·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind99: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
bugzilla·2019-02-22·CVSS 7.5
CVE-2018-5744 [HIGH] CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
CVE-2018-5744 CVE-2018-5745 CVE-2019-6465 bind: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2019-6465 bind: Controls for zone transfers may not be properly applied to DLZs if the zones are writable
bugzilla·2019-02-20·CVSS 5.3
CVE-2019-6465 [MEDIUM] CVE-2019-6465 bind: Controls for zone transfers may not be properly applied to DLZs if the zones are writable
CVE-2019-6465 bind: Controls for zone transfers may not be properly applied to DLZs if the zones are writable
A flaw was found in Bind. Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable. A client exercising this defect can request and receive a zone transfers of a DLZ even when not permitted to do so by the allow-transfer ACL.
Discussion:
External References:
https://kb.isc.org/docs/cve-2019-6465
---
Created bind tracking bugs for this issue:
Affects: fedora-all [bug 1679925]
Created bind99 tracking bugs for this issue:
Affects: fedora-all [bug 1679926]
---
Upstream advisory notes the following versions as being affected by this issue:
9.9.0 -> 9.10.8-P1
9.11.0 -> 9.11.5-P2
9.12.0 -> 9.12.3-P2
9.9.3-S1 -> 9.1
2019-10-09
Published