CVE-2019-6467: An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.c
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-6467?
CVE-2019-6467 is a programming error in the nxdomain-redirect feature in ISC BIND that can cause an assertion failure in query.c.
How does CVE-2019-6467 affect ISC BIND?
CVE-2019-6467 affects ISC BIND versions 9.12.0 to 9.12.4, 9.13.0 to 9.13.7, and 9.14.0 where the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally.
What is the severity of CVE-2019-6467?
The severity of CVE-2019-6467 is high with a CVSS score of 7.5.
How can I fix CVE-2019-6467?
To fix CVE-2019-6467, you should update ISC BIND to a version that includes the necessary patches.
Where can I find more information about CVE-2019-6467?
You can find more information about CVE-2019-6467 on the ISC Knowledge Base website and the Synology Security Advisory website.