CVE-2018-5734: A malformed request can trigger an assertion failure in badcache.c
While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this BIND vulnerability?
The vulnerability ID for this BIND vulnerability is CVE-2018-5734.
What is the severity rating of CVE-2018-5734?
The severity rating of CVE-2018-5734 is 7.5 (high).
How does BIND handle the malformed packet in this vulnerability?
BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode while handling the malformed packet in this vulnerability.
What software versions are affected by CVE-2018-5734?
Versions 9.10.5-s1, 9.10.5-s4, 9.10.6-s1, and 9.10.6-s2 of ISC BIND are affected by CVE-2018-5734.
Where can I find more information about CVE-2018-5734?
More information about CVE-2018-5734 can be found at the following references: [1] [2] [3].