ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND中存在安全漏洞,该漏洞源于程序没有充分地限制TCP客户端同时连接的个数。攻击者可利用该漏洞耗尽文件描述符,影响网络连接和文件管理。以下版本受到影响:BIND 9.9.0版本至9.10.8-P1版本,9.11.0版本至9.11.6版本,9.12.0版本至9.12.4版本,9.14.0版本,9.13.0版本至9.13.7版本(9.13 development branch),BIND 9 Supported Preview E
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ISC | BIND 9 | BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 h | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-6469 | BIND Supported Preview Edition can exit with an assertion failure if ECS is in use | |
| CVE-2019-6471 | A race condition when discarding malformed packets can cause BIND to exit with an assertio | |
| CVE-2018-5732 | A specially constructed response from a malicious server can cause a buffer overflow in dh | |
| CVE-2018-5744 | A specially crafted packet can cause named to leak memory | |
| CVE-2018-5745 | An assertion failure can occur if a trust anchor rolls over to an unsupported key algorith | |
| CVE-2019-6465 | Zone transfer controls for writable DLZ zones were not effective | |
| CVE-2019-6467 | An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion | |
| CVE-2019-6468 | BIND Supported Preview Edition can exit with an assertion failure if nxdomain-redirect is |
No comments yet