CVE-2019-6467
published 2019-10-09CVE-2019-6467: A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.46%
92.2th percentile
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.14.1-r0 | 9.14.1-r0 |
| isc | bind | >= 0 < 9.11.6_p1-r0 | 9.11.6_p1-r0 |
| isc | bind | >= 0 < 9.11.6_p1-r0 | 9.11.6_p1-r0 |
| isc | bind | >= 0 < 9.12.4_p1-r0 | 9.12.4_p1-r0 |
| isc | bind | >= 0 < 9.12.4_p1-r0 | 9.12.4_p1-r0 |
| isc | bind | 9.12.0 – 9.12.4 | — |
| isc | bind | 9.13.0 – 9.13.7 | — |
| isc | bind_9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: flaw in nxredirect can cause assertion failure
vendor_redhat·2019-04-24·CVSS 7.5
CVE-2019-6467 [HIGH] bind: flaw in nxredirect can cause assertion failure
bind: flaw in nxredirect can cause assertion failure
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
A flaw was found in the way "nxdomain-redirect" feature was implemented in bind. An attacker could use this flaw on a server with a vulnerable configuration to caus
Debian
CVE-2019-6467: bind9 - A programming error in the nxdomain-redirect feature can cause an assertion fail...
vendor_debian·2019·CVSS 7.5
CVE-2019-6467 [HIGH] CVE-2019-6467: bind9 - A programming error in the nxdomain-redirect feature can cause an assertion fail...
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-92q8-7pjj-mpmp: A programming error in the nxdomain-redirect feature can cause an assertion failure in query
ghsa_unreviewed·2022-05-24
CVE-2019-6467 [MEDIUM] GHSA-92q8-7pjj-mpmp: A programming error in the nxdomain-redirect feature can cause an assertion failure in query
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
OSV
CVE-2019-6467: A programming error in the nxdomain-redirect feature can cause an assertion failure in query
osv·2019-10-09·CVSS 7.5
CVE-2019-6467 [HIGH] CVE-2019-6467: A programming error in the nxdomain-redirect feature can cause an assertion failure in query
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
No detection rules found.
No public exploits indexed.
2019-10-09
Published