CVE-2019-6471
published 2019-10-09CVE-2019-6471: A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
3.27%
87.0th percentile
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.
Affected
114 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.5.P4+dfsg-5.1 (bookworm) | bind9 1:9.11.5.P4+dfsg-5.1 (bookworm) |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 11.5.2 – 11.5.9 | — |
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.4 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 11.5.2 – 11.5.9 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.4 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.5.2 – 11.5.9 | — |
| f5 | big-ip_analytics | 11.6.1 – 11.6.4 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.1 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerability
vendor_ubuntu·2019-06-20
CVE-2019-6471 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled certain malformed packets.
A remote attacker could possibly use this issue to cause Bind to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure
vendor_redhat·2019-06-19·CVSS 5.9
CVE-2019-6471 [MEDIUM] bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure
bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.
A race condition leading to denial of service was found in the way bind handled certain malformed packets. A remote attacker who could cause the bind resolver to perform queries on a server, which responds deliberately with malformed answers, could cause named to exit.
Statement: This bind fla
Debian
CVE-2019-6471: bind9 - A race condition which may occur when discarding malformed packets can result in...
vendor_debian·2019·CVSS 5.9
CVE-2019-6471 [MEDIUM] CVE-2019-6471: bind9 - A race condition which may occur when discarding malformed packets can result in...
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.
Scope: local
bookworm: resolved (fixed in 1:9.11.5.P4+dfsg-5.1)
bullseye: resolved (fixed in 1:9.11.5.P4+dfsg-5.1)
forky: resolved (fixed in 1:9.11.5.P4+dfsg-5.1)
sid: resolved (fixed in 1:9.11.5.P4+dfsg-5.1)
trixie: resolved (fixed in 1:9.11.5.P4+dfsg-5.1)
GHSA
GHSA-52fp-qxmc-8q94: A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch
ghsa_unreviewed·2022-05-24
CVE-2019-6471 [MEDIUM] CWE-362 GHSA-52fp-qxmc-8q94: A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.
OSV
CVE-2019-6471: A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch
osv·2019-10-09·CVSS 5.9
CVE-2019-6471 [MEDIUM] CVE-2019-6471: A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6471 bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure [fedora-all]
bugzilla·2019-06-20·CVSS 5.9
CVE-2019-6471 [MEDIUM] CVE-2019-6471 bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure [fedora-all]
CVE-2019-6471 bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2019-6471 bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure
bugzilla·2019-06-19·CVSS 5.9
CVE-2019-6471 [MEDIUM] CVE-2019-6471 bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure
CVE-2019-6471 bind: Race condition when discarding malformed packets can cause bind to exit with assertion failure
As per upstream:
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. An attacker who can cause a resolver to perform queries which will be answered by a server which responds with deliberately malformed answers can cause named to exit, denying service to clients.
Discussion:
Acknowledgments:
Name: ISC
---
Created attachment 1582061
bind patch for 9.11.8
---
Created attachment 1582062
bind-9.12.4-p2 patch
---
Statement:
This bind flaw can be exploited by a remote attacker (AV:N). However the attack works only if the attacker could cause the bind server to perform queries on a
2019-10-09
Published