CVE-2019-6476
published 2019-10-17CVE-2019-6476: A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.91%
86.1th percentile
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| chrome_chrome | — | — | |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | >= 0 < 9.14.7-r0 | 9.14.7-r0 |
| isc | bind | 9.14.0 – 9.14.6 | — |
| isc | bind | 9.15.0 – 9.15.4 | — |
| isc | bind_9 | — | — |
| isc | bind_9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2020-6475
vendor_chrome·2020-05-19·CVSS 6.5
CVE-2020-6475 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6475
Stable Channel Update for Desktop
CVE-2020-6475: Incorrect security UI in full screen. Reported by Khalil Zhani on 2019-10-31
[$1000][ 1035315 ] Medium CVE-2020-6476: Insufficient policy enforcement in tab strip
Reported by Alexandre Le Borgne on 2019-12-18
Severity: medium
Red Hat
bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure
vendor_redhat·2019-10-16·CVSS 5.9
CVE-2019-6476 [MEDIUM] CWE-617 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure
bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
Statement: This flaw did not affect the versions of bind shipped with Red Hat Enterprise Linux 6, 7 and 8.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-6476: bind9 - A defect in code added to support QNAME minimization can cause named to exit wit...
vendor_debian·2019·CVSS 5.9
CVE-2019-6476 [MEDIUM] CVE-2019-6476: bind9 - A defect in code added to support QNAME minimization can cause named to exit wit...
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-7rr8-wvj2-chhv: A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than r
ghsa_unreviewed·2022-05-24
CVE-2019-6476 [HIGH] CWE-617 GHSA-7rr8-wvj2-chhv: A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than r
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
OSV
CVE-2019-6476: A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than r
osv·2019-10-17·CVSS 7.5
CVE-2019-6476 [HIGH] CVE-2019-6476: A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than r
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6476 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure
bugzilla·2019-10-17·CVSS 5.9
CVE-2019-6476 [MEDIUM] CVE-2019-6476 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure
CVE-2019-6476 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query.
https://kb.isc.org/docs/cve-2019-6476
Discussion:
Created bind tracking bugs for this issue:
Affects: fedora-all [bug 1762958]
---
External References:
https://kb.isc.org/docs/cve-2019-6476
---
Upstream commit (9.15 branch):
https://gitlab.isc.org/isc-projects/bind9/commit/6923a80357d634ee7b701c1ad4fad9b3db95f8c8
---
Statement:
This flaw did not affect the versions of bind shipped with Red Hat Enterprise Linux 6, 7 and 8.
---
This bug is now closed. Further updates for individual products will be reflect
Bugzilla
CVE-2019-6476 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure [fedora-all]
bugzilla·2019-10-17·CVSS 5.9
CVE-2019-6476 [MEDIUM] CVE-2019-6476 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure [fedora-all]
CVE-2019-6476 bind: An error in QNAME minimization code can cause BIND to exit with an assertion failure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2019-9658 checkstyle: Loads external DTDs by default
bugzilla·2019-04-01·CVSS 5.3
CVE-2019-9658 [MEDIUM] CVE-2019-9658 checkstyle: Loads external DTDs by default
CVE-2019-9658 checkstyle: Loads external DTDs by default
Checkstyle before 8.18 loads external DTDs by default.
Upstream issue:
https://github.com/checkstyle/checkstyle/issues/6474
https://github.com/checkstyle/checkstyle/issues/6478
Upstream patch:
https://github.com/checkstyle/checkstyle/pull/6476
References:
https://checkstyle.org/releasenotes.html#Release_8.18
Discussion:
Created checkstyle tracking bugs for this issue:
Affects: fedora-all [bug 1694858]
---
checkstyle-8.0-4.1.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.
---
checkstyle-8.0-4.1.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.
---
This CVE Bugzilla
https://kb.isc.org/docs/cve-2019-6476https://security.netapp.com/advisory/ntap-20191024-0004/https://support.f5.com/csp/article/K42238532?utm_source=f5support&%3Butm_medium=RSShttps://kb.isc.org/docs/cve-2019-6476https://security.netapp.com/advisory/ntap-20191024-0004/https://support.f5.com/csp/article/K42238532?utm_source=f5support&%3Butm_medium=RSS
2019-10-17
Published