Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-5734


While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2.


Published

2019-01-16T20:29:00.800

Last Modified

2024-11-21T04:09:16.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application isc bind 9.10.5 Yes
Application isc bind 9.10.5 Yes
Application isc bind 9.10.6 Yes
Application isc bind 9.10.6 Yes
Application netapp data_ontap_edge - Yes
Application netapp solidfire_element_os_management_node - Yes

References