A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Oct 9, 2019 | Oct 9, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 9, 2019 | May 9, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade bind-pkcs11-libsUpgrade bind-chrootUpgrade python3-bindUpgrade bindUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-utilsUpgrade bind-pkcs11Upgrade bind-libs-liteUpgrade bind-licenseUpgrade bind-export-develUpgrade bind-export-libs | Feb 26, 2020 | Oct 9, 2019 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.11.6.1.0-11.4.11.0.1.2.0 on Solaris 11.4 | Jul 17, 2019 | Jul 17, 2019 |
| Suse | — | Upgrade libirs1601Upgrade libns1604Upgrade libdns1605Upgrade libisc1606Upgrade bind-develUpgrade libbind9-1600Upgrade libisccc1600Upgrade libisccfg1600Upgrade python3-bindUpgrade bind-chrootenvUpgrade bind-utilsUpgrade bind-docUpgrade bindUpgrade libirs-devel | Feb 4, 2022 | Oct 9, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub