While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bind-sdbUpgrade bindUpgrade bind-chrootUpgrade bind-pkcs11Upgrade bind-debuginfoUpgrade bind-develUpgrade bind-libs-liteUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-utilsUpgrade bind-lite-develUpgrade bind-utilsUpgrade bind-libsUpgrade bind-pkcs11-develUpgrade bind-licenseUpgrade bind-sdb-chroot | Apr 27, 2020 | Oct 30, 2019 |
| Centos_linux | — | Upgrade bind-chrootUpgrade bind-sdbUpgrade bind-debuginfoUpgrade bind-libsUpgrade bind-utilsUpgrade bind-lite-develUpgrade bindUpgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bind-pkcs11Upgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-sdb-chrootUpgrade bind-devel | Feb 5, 2019 | Jan 29, 2019 |
| Oracle_linux | — | Upgrade bind-sdb-chrootUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-develUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind-sdbUpgrade bind-pkcs11-libsUpgrade bind-lite-develUpgrade bind-chrootUpgrade bind-pkcs11-develUpgrade bind-libs-liteUpgrade bind-utils | Jan 30, 2019 | Dec 18, 2018 |
| Redhat_linux | — | Upgrade bind-lite-develUpgrade bindUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-develUpgrade bind-debuginfoUpgrade bind-sdbUpgrade bind-utilsUpgrade bind-pkcs11Upgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-sdb-chrootUpgrade bind-pkcs11-develUpgrade bind-libsUpgrade bind-license | Jan 30, 2019 | Jan 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub