Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.146634
Category:Denial of Service
Title:ISC BIND DoS Vulnerability (CVE-2018-5734) - Linux
Summary:ISC BIND is prone to a denial of service (DoS) vulnerability.
Description:Summary:
ISC BIND is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
While handling a particular type of malformed packet, BIND
erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the
SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the
request doesn't contain all of the expected information.

Vulnerability Impact:
Servers running the affected versions are vulnerable if they
allow recursion, unless the SERVFAIL cache is disabled for the receiving view.

Affected Software/OS:
BIND 9.10.5-S1 through 9.10.5-S4, 9.10.6-S1 and 9.10.6-S2.

Solution:
Update to version 9.10.6-S3 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-5734
BugTraq ID: 103189
http://www.securityfocus.com/bid/103189
http://www.securitytracker.com/id/1040438
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.