An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jan 16, 2019 | Jan 16, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 23, 2018 | May 23, 2018 |
| Freebsd | — | Upgrade bind912 | May 22, 2018 | May 21, 2018 |
| Suse | — | Upgrade python3-bindUpgrade libisc1606Upgrade libns1604Upgrade libirs1601Upgrade bind-docUpgrade libisccfg1600Upgrade libisccc1600Upgrade bind-chrootenvUpgrade libbind9-1600Upgrade bind-develUpgrade bind-utilsUpgrade libirs-develUpgrade libdns1605Upgrade bind | Feb 4, 2022 | May 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub