Use of a broken or risky cryptographic algorithm in ISC BIND - CVE-2018-5745
Published: October 9, 2019 / Updated: July 24, 2020
Vulnerability details
The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
Affected software
Arch Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
bind (Alpine package)
bind (Red Hat package) main
bind
Data Computing Appliance (DCA)
How to mitigate CVE-2018-5745
Data Computing Appliance (DCA) - update to 4.3.0.0
bind (Red Hat package) main - addressed in versions 9.11.4-16.P2.el7, 9.11.4-26.P2.el8
bind - addressed in versions 9.11.5-4.P4.fc28, 9.11.5-4.P4.fc29
External References
Related Security Bulletins
- Use of a broken or risky cryptographic algorithm in ISC BIND
- OpenSUSE Linux update for bind
- OpenSUSE Linux update for bind
- Use of a broken or risky cryptographic algorithm in bind (Alpine package)
- Arch Linux update for bind
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 7 update for bind
- Fedora 29 update for bind
- Fedora 28 update for bind