First published: Wed Oct 09 2019(Updated: )
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
Credit: security-officer@isc.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND | >=9.12.0<=9.12.4 | |
ISC BIND | >=9.13.0<=9.13.7 | |
ISC BIND | =9.14.0 |
Upgrade to the patched release most closely related to your current version of BIND: + BIND 9.12.4-P1 + BIND 9.14.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6467 is a programming error in the nxdomain-redirect feature in ISC BIND that can cause an assertion failure in query.c.
CVE-2019-6467 affects ISC BIND versions 9.12.0 to 9.12.4, 9.13.0 to 9.13.7, and 9.14.0 where the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally.
The severity of CVE-2019-6467 is high with a CVSS score of 7.5.
To fix CVE-2019-6467, you should update ISC BIND to a version that includes the necessary patches.
You can find more information about CVE-2019-6467 on the ISC Knowledge Base website and the Synology Security Advisory website.