Assertion failure in ISC BIND - CVE-2018-5737
Published: May 21, 2018
Vulnerability identifier: #VU12857
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5737
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists on the systems that permit recursion to clients and that have the max-stale-ttl parameter set to a non-zero value due to a flaw in the serve-stale implementation even when serve-stale is not enabled. A remote attacker can trigger an assertion failure in rbtdb.c cause performance degradation on the target system such as recursion loops or excessive logging.
Affected software
ISC BIND
Arch Linux
bind (Alpine package)
Arch Linux
bind (Alpine package)
How to mitigate CVE-2018-5737
Update to version 9.12.1-P1.
bind (Alpine package) - update to 9.12.1_p2-r0