Memory Leak Affecting bind package, versions [9.10.7,9.10.8)[9.11.3,9.11.5)[9.12.0,9.12.3)[9.13.0,9.13.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.52% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-BIND-2382018
  • published26 Jan 2022
  • disclosed9 Oct 2019
  • creditUnknown

Introduced: 9 Oct 2019

CVE-2018-5744  (opens in a new tab)
CWE-772  (opens in a new tab)

How to fix?

Upgrade bind to version 9.10.8, 9.11.5, 9.12.3, 9.13.6 or higher.

Overview

Affected versions of this package are vulnerable to Memory Leak. A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.

References

CVSS Scores

version 3.1