Assertion failure in ISC BIND - CVE-2017-3138
Published: November 28, 2018
ISC BIND
Detailed vulnerability description
The vulnerability exists due to named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc.. A remote attacker can send some versions of named a null command string, trigger a REQUIRE assertion failure and cause the service to crash.