An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jan 13, 2017 | Jan 13, 2017 |
| Freebsd | — | Upgrade bind910Upgrade bind911Upgrade FreeBSDUpgrade bind99Upgrade bind9-devel | Jan 12, 2017 | Jan 12, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade libisccc1600Upgrade libisc1606Upgrade bind-utilsUpgrade liblwres160Upgrade libbind9-1600Upgrade python3-bindUpgrade libisccc160Upgrade libns1604Upgrade libdns1605Upgrade libisccfg1600Upgrade libisccfg160Upgrade libirs1601Upgrade bindUpgrade libirs160Upgrade libisc166Upgrade libbind9-160Upgrade bind-docUpgrade libirs-develUpgrade bind-develUpgrade bind-chrootenvUpgrade libdns169 | May 20, 2018 | Jan 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub