CVE-2018-5736
This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 18.02% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- isc/bind · netapp/cloud backup · netapp/data ontap edge
- Source
- security-officer@isc.org
References
- http://www.securityfocus.com/bid/104386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040941Third Party Advisory, VDB Entry
- https://kb.isc.org/docs/aa-01602Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180926-0004/Third Party Advisory
- http://www.securityfocus.com/bid/104386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040941Third Party Advisory, VDB Entry
- https://kb.isc.org/docs/aa-01602Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180926-0004/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.