CVE-2019-6469
published 2019-10-09CVE-2019-6469: An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.96%
79.0th percentile
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview Edition.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind_9_supported_preview_edition | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qxvj-gg4r-8gwm: An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response t
ghsa_unreviewed·2022-05-24
CVE-2019-6469 [HIGH] CWE-617 GHSA-qxvj-gg4r-8gwm: An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response t
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview Edition.
Red Hat
bind: an error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure leading to DoS
vendor_redhat·2019-05-30·CVSS 7.5
CVE-2019-6469 [HIGH] CWE-20 bind: an error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure leading to DoS
bind: an error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure leading to DoS
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview Edition.
Statement: This flaw only affects the BIND Supported Preview Edition version. Packages shipped with Red Hat Enterprise Linux are not affected by this flaw.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2019-6469: bind9 - An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cau...
vendor_debian·2019·CVSS 7.5
CVE-2019-6469 [HIGH] CVE-2019-6469: bind9 - An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cau...
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview Edition.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2019-10-09
Published