CVE-2019-6477
published 2019-11-26CVE-2019-6477: With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.06%
89.6th percentile
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.14+dfsg-1 (bookworm) | bind9 1:9.11.14+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome_chrome | — | — | |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.11.7 – 9.11.12 | — |
| isc | bind | 9.14.1 – 9.14.7 | — |
| isc | bind | 9.15.0 – 9.15.5 | — |
| isc | bind9 | — | — |
| isc | bind9 | >= 0 < 1:9.11.14+dfsg-1 | 1:9.11.14+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.14+dfsg-1 | 1:9.11.14+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.14+dfsg-1 | 1:9.11.14+dfsg-1 |
| isc | bind9 | >= 0 < 1:9.11.14+dfsg-1 | 1:9.11.14+dfsg-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6q2x-892r-7qm4: With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without
ghsa_unreviewed·2022-05-24
CVE-2019-6477 [HIGH] CWE-400 GHSA-6q2x-892r-7qm4: With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
OSV
CVE-2019-6477: With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without
osv·2019-11-26·CVSS 7.5
CVE-2019-6477 [HIGH] CVE-2019-6477: With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
Chrome
Stable Channel Update for Desktop: CVE-2020-6477
vendor_chrome·2020-05-19·CVSS 7.8
CVE-2020-6477 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6477
Stable Channel Update for Desktop
CVE-2020-6477: Inappropriate implementation in installer. Reported by RACK911 Labs on 2019-03-26
[$500][ 1037730 ] Medium CVE-2020-6478: Inappropriate implementation in full screen
Reported by Khalil Zhani on 2019-12-24
Severity: medium
Ubuntu
Bind vulnerability
vendor_ubuntu·2019-11-21
CVE-2019-6477 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to consume resources if it received specially crafted
network traffic.
It was discovered that Bind incorrectly handled certain TCP-pipelined
queries. A remote attacker could possibly use this issue to cause Bind to
consume resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: TCP Pipelining doesn't limit TCP clients on a single connection
vendor_redhat·2019-11-20·CVSS 7.5
CVE-2019-6477 [HIGH] CWE-400 bind: TCP Pipelining doesn't limit TCP clients on a single connection
bind: TCP Pipelining doesn't limit TCP clients on a single connection
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
A flaw was found in the way bind limited the number of TCP clients that can be connected at any given time. A remote
Debian
CVE-2019-6477: bind9 - With pipelining enabled each incoming query on a TCP connection requires a simil...
vendor_debian·2019·CVSS 7.5
CVE-2019-6477 [HIGH] CVE-2019-6477: bind9 - With pipelining enabled each incoming query on a TCP connection requires a simil...
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
Scope: local
bookworm: resolved (fixed in 1:9.11.14+dfsg-1)
bullseye: resolved (fixed in 1:9.11.14+dfsg-1)
forky: resolved (fixed in 1:9.11.14+dfsg-1)
sid: resolved (fixed in 1:9.11.14+dfs
No detection rules found.
No public exploits indexed.
arXiv
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
arxiv_fulltext·2023-10-04
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
https://faculty.sites.uci.edu/zhouli/research/ Qifan Zhang ,
https://faculty.sites.uci.edu/zhouli/research/ Xuesong Bai ,
https://netsec.ccert.edu.cn/people/lx19 Xiang Li ,
https://netsec.ccert.edu.cn/people/duanhx/ Haixin Duan ,
https://netsec.ccert.edu.cn/people/qli/ Qi Li , and
https://faculty.sites.uci.edu/zhouli/ Zhou Li
Corresponding authors. Most of Xiang Li's work was done when visiting UCI as a project specialist.
https://uci.edu/University of California, Irvine,
https://www.tsinghua.edu.cn/en/Tsinghua University
Zhongguancun Laboratory,
https://www.qcl.edu.cn/Quan Cheng Laboratory
## Abstract
Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache
Bugzilla
CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection [fedora-all]
bugzilla·2019-11-21·CVSS 7.5
CVE-2019-6477 [HIGH] CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection [fedora-all]
CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection
bugzilla·2019-11-18·CVSS 7.5
CVE-2019-6477 [HIGH] CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection
CVE-2019-6477 bind: TCP Pipelining doesn't limit TCP clients on a single connection
As per upstream advisory:
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The update to this functionality introduced by CVE-2018-5743 changed how BIND calculates the number of concurrent TCP clients from counting the outstanding TCP queries to counting the TCP client connections. On a server with TCP-pipelining capability, it is possible for one TCP client to send a large number of DNS requests over a single connection. Each outstanding query will be handled internally as an independent client request, thus bypassing the new TCP clients limit.
Discussion:
Acknowledgments:
Name: ISC
---
Created attachment 1637475
patch against 9.11.13
---
Plea
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2019-6477https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3DEMNZMKR57VQJCG5ZN55ZGTQRL2TFQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGURMGQHX45KR4QDRCSUQHODUFOGNGAN/https://support.f5.com/csp/article/K15840535?utm_source=f5support&%3Butm_medium=RSShttps://www.debian.org/security/2020/dsa-4689https://www.synology.com/security/advisory/Synology_SA_19_39http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2019-6477https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3DEMNZMKR57VQJCG5ZN55ZGTQRL2TFQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGURMGQHX45KR4QDRCSUQHODUFOGNGAN/https://support.f5.com/csp/article/K15840535?utm_source=f5support&%3Butm_medium=RSShttps://www.debian.org/security/2020/dsa-4689https://www.synology.com/security/advisory/Synology_SA_19_39
2019-11-26
Published