cbcvebase.
CVE-2019-6475
published 2019-10-17

CVE-2019-6475: Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.27%
68.0th percentile
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing. The mirror zone feature is most often used to serve a local copy of the root zone. If an attacker was able to insert themselves into the network path between a recursive server using a mirror zone and a root name server, this vulnerability could then be used to cause the recursive server to accept a copy of falsified root zone data. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianbind9
googlechrome_chrome
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind>= 0 < 9.14.7-r09.14.7-r0
iscbind9.14.0 – 9.14.6
iscbind9.15.0 – 9.15.4
iscbind_9
iscbind_9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.