Security restrictions bypass in ISC BIND - CVE-2018-5741

 

Security restrictions bypass in ISC BIND - CVE-2018-5741

Published: November 23, 2018 / Updated: November 24, 2018


Vulnerability identifier: #VU16033
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5741
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.

The vulnerability exists due to an error in the documentation of the 'update-policy' feature for the 'krb5-subdomain' and 'ms-subdomain' update policies. A remote attacker can bypass security restrictions to modify records in the zone at or below the name specified in the name field.


Affected software

ISC BIND
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Opensuse
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
bind (Alpine package)
bind
Data Computing Appliance (DCA)

How to mitigate CVE-2018-5741

The vulnerability has been addressed in the versions 9.11.5, 9.12.3.

ISC BIND - addressed in versions 9.11.5, 9.12.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
bind (Alpine package) - addressed in versions 9.11.5-r0, 9.12.3-r0
Data Computing Appliance (DCA) - update to 4.3.0.0
bind - addressed in versions 9.11.4-3.P2.fc27, 9.11.4-10.P2.fc28, 9.11.4-10.P2.fc29

External References

Related Security Bulletins