Denial of Service (DoS) Affecting bind package, versions [9.12.0,9.12.1-P1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
18.02% (97th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-BIND-2382028
  • published26 Jan 2022
  • disclosed16 Jan 2019
  • creditUnknown

Introduced: 16 Jan 2019

CVE-2018-5736  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

Upgrade bind to version 9.12.1-P1 or higher.

Overview

Affected versions of this package are vulnerable to Denial of Service (DoS). An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.

References

CVSS Base Scores

version 3.1