Allocation of Resources Without Limits or Throttling in ISC BIND - CVE-2018-5743
Published: October 9, 2019 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
bind (Alpine package)
dnsperf
dhcp
bind (Red Hat package) main
bind
bind-chroot
bind-devel
bind-export-devel
bind-export-libs
bind-libs
bind-libs-lite
bind-lite-devel
bind-pkcs11
bind-pkcs11-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-utils
bind-license
python3-bind
bind-dyndb-ldap
Data Computing Appliance (DCA)
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2018-5743
dnsperf - addressed in versions 2.2.1-4.fc29, 2.2.1-4.fc30
Data Computing Appliance (DCA) - update to 3.5.4.0
dhcp - addressed in versions 4.3.6-31.fc29, 4.3.6-34.fc30
bind (Red Hat package) main - addressed in versions 9.8.2-0.68.rc1.el6_10.3, 9.9.4-51.el7_4.3, 9.9.4-61.el7_5.2, 9.9.4-74.el7_6.1, 9.11.4-17.P2.el8_0
bind - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind - addressed in versions 9.11.6-2.P1.fc29, 9.11.6-3.P1.fc30
python3-bind - update to 9.11.36-3
bind-dyndb-ldap - addressed in versions 11.1-15.fc29, 11.1-15.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
Related Security Bulletins
- Allocation of Resources Without Limits or Throttling in ISC BIND
- OpenSUSE Linux update for bind
- OpenSUSE Linux update for bind
- Allocation of Resources Without Limits or Throttling in bind (Alpine package)
- Amazon Linux AMI update for bind
- Slackware Linux update for bind
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 7 update for bind
- Red Hat Enterprise Linux 6 update for bind
- Red Hat Enterprise Linux 7.4 Extended Update Support update for bind
- Red Hat Enterprise Linux 7.5 Extended Update Support update for bind
- Anolis OS update for bind (Anolis OS 8.6)
- Anolis OS update for bind
- Fedora 30 update for bind, bind-dyndb-ldap, dhcp, dnsperf
- Fedora 29 update for bind, bind-dyndb-ldap, dhcp, dnsperf