7.5
CVE-2018-5740
- EPSS 59.62%
- Veröffentlicht 16.01.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:17
- Erkennungen
A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Server Eus Version 7.6
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Data Ontap Edge Version -
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 59.62% | 0.99 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
| ISC | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://security.gentoo.org/glsa/201903-13
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00027.html
http://www.securityfocus.com/bid/105055
http://www.securitytracker.com/id/1041436
https://access.redhat.com/errata/RHSA-2018:2570
https://access.redhat.com/errata/RHSA-2018:2571
https://kb.isc.org/docs/aa-01639
https://lists.debian.org/debian-lts-announce/2018/08/msg00033.html
https://lists.debian.org/debian-lts-announce/2021/11/msg00001.html
https://security.netapp.com/advisory/ntap-20180926-0003/
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03927en_us
https://usn.ubuntu.com/3769-1/
https://usn.ubuntu.com/3769-2/