First published: Wed Jan 16 2019(Updated: )
While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2.
Credit: security-officer@isc.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND | =9.10.5-s1 | |
ISC BIND | =9.10.5-s4 | |
ISC BIND | =9.10.6-s1 | |
ISC BIND | =9.10.6-s2 | |
Netapp Data Ontap Edge | ||
Netapp Solidfire Element Os Management Node |
Upgrade to the patched release. No publicly released versions of BIND are affected BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. BIND 9 version 9.10.6-S3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this BIND vulnerability is CVE-2018-5734.
The severity rating of CVE-2018-5734 is 7.5 (high).
BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode while handling the malformed packet in this vulnerability.
Versions 9.10.5-s1, 9.10.5-s4, 9.10.6-s1, and 9.10.6-s2 of ISC BIND are affected by CVE-2018-5734.
More information about CVE-2018-5734 can be found at the following references: [1] [2] [3].