CVE-2019-6475
published 2019-10-17CVE-2019-6475: Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.27%
68.0th percentile
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing. The mirror zone feature is most often used to serve a local copy of the root zone. If an attacker was able to insert themselves into the network path between a recursive server using a mirror zone and a root name server, this vulnerability could then be used to cause the recursive server to accept a copy of falsified root zone data. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| chrome_chrome | — | — | |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | 9.14.0 – 9.14.6 | — |
| isc | bind | 9.15.0 – 9.15.4 | — |
| isc | bind_9 | — | — |
| isc | bind_9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2020-6475
vendor_chrome·2020-05-19·CVSS 6.5
CVE-2020-6475 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6475
Stable Channel Update for Desktop
CVE-2020-6475: Incorrect security UI in full screen. Reported by Khalil Zhani on 2019-10-31
[$1000][ 1035315 ] Medium CVE-2020-6476: Insufficient policy enforcement in tab strip
Reported by Alexandre Le Borgne on 2019-12-18
Severity: medium
Red Hat
bind: A flaw in mirror zone validity checking can allow zone data to be spoofed
vendor_redhat·2019-10-16·CVSS 5.9
CVE-2019-6475 [MEDIUM] CWE-290 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed
bind: A flaw in mirror zone validity checking can allow zone data to be spoofed
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing. The mirror zone feature is most often used to serve a local copy of the root zone.
Debian
CVE-2019-6475: bind9 - Mirror zones are a BIND feature allowing recursive servers to pre-cache zone dat...
vendor_debian·2019·CVSS 5.9
CVE-2019-6475 [MEDIUM] CVE-2019-6475: bind9 - Mirror zones are a BIND feature allowing recursive servers to pre-cache zone dat...
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing. The mirror zone feature is most often used to serve a local copy of the root zone. If an attacker was able to insert themselves into the network path between a rec
GHSA
GHSA-2gfp-93f7-f268: Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers
ghsa_unreviewed·2022-05-24
CVE-2019-6475 [HIGH] CWE-345 GHSA-2gfp-93f7-f268: Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing. The mirror zone feature is most often used to serve a local copy of the root zone. If an attacker was able to insert themselves into the network path between a rec
OSV
CVE-2019-6475: Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers
osv·2019-10-17·CVSS 7.5
CVE-2019-6475 [HIGH] CVE-2019-6475: Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing. The mirror zone feature is most often used to serve a local copy of the root zone. If an attacker was able to insert themselves into the network path between a rec
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6475 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed [fedora-all]
bugzilla·2019-10-17·CVSS 5.9
CVE-2019-6475 [MEDIUM] CVE-2019-6475 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed [fedora-all]
CVE-2019-6475 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2019-6475 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed
bugzilla·2019-10-17·CVSS 5.9
CVE-2019-6475 [MEDIUM] CVE-2019-6475 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed
CVE-2019-6475 bind: A flaw in mirror zone validity checking can allow zone data to be spoofed
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via traditional recursion, and when mirror zone data cannot be validated, BIND falls back to using traditional recursion instead of the mirror zone. However, an error in the validity checks for the incoming zone data can allow an on-path attacker to replace zone data that was validated with a configured trust anchor with forged data of the attacker's choosing.
The mirror zone feature is most often used to serve a local copy of
https://kb.isc.org/docs/cve-2019-6475https://security.netapp.com/advisory/ntap-20191024-0004/https://support.f5.com/csp/article/K42238532?utm_source=f5support&%3Butm_medium=RSShttps://kb.isc.org/docs/cve-2019-6475https://security.netapp.com/advisory/ntap-20191024-0004/https://support.f5.com/csp/article/K42238532?utm_source=f5support&%3Butm_medium=RSS
2019-10-17
Published