Assertion failure in ISC BIND - CVE-2018-5736
Published: May 21, 2018
Vulnerability identifier: #VU12860
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5736
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The weakness exists due to an error in zone database reference counting. A remote authenticated attacker who is able to cause the target server to initiate zone transfers (e.g., can send NOTIFY messages) can cause several transfers of a slave zone in quick succession to trigger an assertion in 'rbtdb.c' and cause 'named' to crash.
Affected software
ISC BIND
Arch Linux
bind (Alpine package)
Arch Linux
bind (Alpine package)
How to mitigate CVE-2018-5736
Update to version 9.12.1-P1.
bind (Alpine package) - update to 9.12.1_p2-r0