named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jan 16, 2019 | Jan 16, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Debian | — | Upgrade bind9 | May 15, 2017 | Apr 12, 2017 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 15, 2017 | May 15, 2017 |
| Freebsd | — | Upgrade bind99Upgrade bind911Upgrade bind9-develUpgrade bind910 | Apr 13, 2017 | Apr 13, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 19, 2018 |
| Suse | — | Upgrade libirs-develUpgrade libisc166Upgrade libbind9-160Upgrade bindUpgrade libdns169Upgrade bind-docUpgrade bind-devel-32bitUpgrade bind-libsUpgrade bind-develUpgrade libisccc1600Upgrade bind-chrootenvUpgrade libirs160Upgrade libbind9-1600Upgrade libdns1605Upgrade libns1604Upgrade python-bindUpgrade libisc1606Upgrade python3-bindUpgrade libisccfg160Upgrade libisccc160Upgrade bind-utilsUpgrade bind-libs-x86Upgrade libisccfg1600Upgrade liblwres160Upgrade bind-libs-32bitUpgrade libisc166-32bitUpgrade libirs1601 | Apr 13, 2017 | Apr 12, 2017 |
| Ubuntu | — | Upgrade bind9 | Apr 17, 2017 | Apr 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub