named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jan 16, 2019 | Jan 16, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Debian | — | Upgrade bind9 | May 15, 2017 | Apr 12, 2017 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 15, 2017 | May 15, 2017 |
| Freebsd | — | Upgrade bind911Upgrade bind9-develUpgrade bind910Upgrade bind99 | Apr 13, 2017 | Apr 13, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 19, 2018 |
| Suse | — | Upgrade libisc1606Upgrade libdns1605Upgrade python-bindUpgrade bind-utilsUpgrade libns1604Upgrade bind-libs-x86Upgrade liblwres160Upgrade python3-bindUpgrade libisccfg160Upgrade libirs1601Upgrade libisc166-32bitUpgrade libisccfg1600Upgrade bind-libs-32bitUpgrade libisccc160Upgrade libdns169Upgrade libisc166Upgrade libirs-develUpgrade bind-devel-32bitUpgrade bind-libsUpgrade bind-chrootenvUpgrade libisccc1600Upgrade libirs160Upgrade bindUpgrade libbind9-1600Upgrade bind-docUpgrade bind-develUpgrade libbind9-160 | Apr 13, 2017 | Apr 12, 2017 |
| Ubuntu | — | Upgrade bind9 | Apr 17, 2017 | Apr 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub