CVE-2018-5741: Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentation
ISC BIND before releases 9.11.4-P2 and 9.12.2-P2 does not properly document the behaviour of the krb5-subdomain and ms-subdomain update policies. This incorrect documentation could mislead operators into believing that policies they had configured were more restrictive than they actually were.
The krb5-subdomain and ms-subdomain update policy rule types permit updates from any client authenticated with a valid Kerberos or Windows machine principal from the REALM specified in the identity field, to modify records in the zone at or below the name specified in the name field. The incorrect documentation, however, indicated that the policy would be restricted to names at or below the machine's name as encoded in the Windows or Kebreros principal.
External Reference:
https://kb.isc.org/docs/cve-2018-5741
Other sources
To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. Unfortunately, some rule types were not initially documented, and when documentation for them was added to the Administrator Reference Manual (ARM) in change #3112, the language that was added to the ARM at that time incorrectly described the behavior of two rule types, krb5-subdomain and ms-subdomain. This incorrect documentation could mislead operators into believing that policies they had configured were more restrictive than they actually were. This affects BIND versions prior to BIND 9.11.5 and BIND 9.12.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5741?
The severity of CVE-2018-5741 is medium, with a severity value of 6.5.
How does CVE-2018-5741 affect BIND?
CVE-2018-5741 affects BIND versions 9.11.5 up to 9.12.3.
What is the update-policy feature in BIND?
The update-policy feature in BIND provides fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone.
How can I limit the types of updates performed by a client in BIND?
You can use the update-policy feature in BIND to configure various rules that limit the types of updates that can be performed by a client, depending on the key used when sending the update.
Where can I find more information about CVE-2018-5741?
You can find more information about CVE-2018-5741 at the following references: http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html, http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html, and http://www.securityfocus.com/bid/105379.