CVE-2019-6469
- EPSS 1.96%
- Veröffentlicht 09.10.2019 16:15:17
- Zuletzt bearbeitet 21.11.2024 04:46:30
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview...
CVE-2019-6471
- EPSS 3.3%
- Veröffentlicht 09.10.2019 16:15:17
- Zuletzt bearbeitet 21.11.2024 04:46:30
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the ...
CVE-2019-6465
- EPSS 3.73%
- Veröffentlicht 09.10.2019 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:46:30
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 ...
CVE-2019-6467
- EPSS 5.46%
- Veröffentlicht 09.10.2019 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:46:30
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is i...
CVE-2019-6468
- EPSS 2.56%
- Veröffentlicht 09.10.2019 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:46:30
In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. In those versions which have ECS support, enabling nxdomain-redirect is likely to lead to BIND exiting...
CVE-2018-5745
- EPSS 2.28%
- Veröffentlicht 09.10.2019 16:15:14
- Zuletzt bearbeitet 01.09.2026 19:44:42
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server whi...
CVE-2018-5743
- EPSS 6.46%
- Veröffentlicht 09.10.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:09:17
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the co...
CVE-2018-5744
- EPSS 3.38%
- Veröffentlicht 09.10.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:09:18
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Suppor...
CVE-2018-5740
- EPSS 59.62%
- Veröffentlicht 16.01.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:17
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feat...
CVE-2018-5741
- EPSS 3.48%
- Veröffentlicht 16.01.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:17
To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, ...