named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jan 16, 2019 | Jan 16, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Debian | — | Upgrade bind9 | May 15, 2017 | Apr 12, 2017 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 15, 2017 | May 15, 2017 |
| Freebsd | — | Upgrade bind911Upgrade bind9-develUpgrade bind99Upgrade bind910 | Apr 13, 2017 | Apr 13, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 19, 2018 |
| Suse | — | Upgrade libns1604Upgrade libirs1601Upgrade bind-utilsUpgrade libisccfg160Upgrade libisc166-32bitUpgrade libisccc160Upgrade python3-bindUpgrade libdns1605Upgrade bind-libs-32bitUpgrade libisc1606Upgrade liblwres160Upgrade bind-libs-x86Upgrade libisccfg1600Upgrade python-bindUpgrade bind-libsUpgrade libisccc1600Upgrade libisc166Upgrade bind-chrootenvUpgrade libbind9-160Upgrade bindUpgrade libirs160Upgrade bind-develUpgrade bind-devel-32bitUpgrade libirs-develUpgrade bind-docUpgrade libdns169Upgrade libbind9-1600 | Apr 13, 2017 | Apr 12, 2017 |
| Ubuntu | — | Upgrade bind9 | Apr 17, 2017 | Apr 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub