CVE-2018-5741
Last modified
CVE-2018-5741 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. Unfortunately, some rule types were not initially documented, and when documentation for them was added to the Administrator Reference Manual (ARM) in change #3112, the language that was added to the ARM at that time incorrectly described the behavior of two rule types, krb5-subdomain and ms-subdomain. This incorrect documentation could mislead operators into believing that policies they had configured were more restrictive than they actually were. This affects BIND versions prior to BIND 9.11.5 and BIND 9.12.3.
Metrics
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Isc | Bind | < 9.11.5 |
| Isc | Bind | >= 9.12.0, < 9.12.3 |
References
- http://www.securityfocus.com/bid/105379Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041674Third Party Advisory, VDB Entry
- https://kb.isc.org/docs/cve-2018-5741Vendor Advisory
- https://security.gentoo.org/glsa/201903-13Third Party Advisory
- http://www.securityfocus.com/bid/105379Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041674Third Party Advisory, VDB Entry
- https://kb.isc.org/docs/cve-2018-5741Vendor Advisory
- https://security.gentoo.org/glsa/201903-13Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5741?
How severe is CVE-2018-5741?
How do I fix CVE-2018-5741?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5735The Debian backport of the fix for CVE-2017-3137 leads to as…7.5
- CVE-2018-5736An error in zone database reference counting can lead to an …
- CVE-2018-5737A problem with the implementation of the new serve-stale fea…5.9
- CVE-2018-5738Change #4777 (introduced in October 2017) introduced an unfo…5.3
- CVE-2018-5739An extension to hooks capabilities which debuted in Kea 1.4.…6.5
- CVE-2018-5740"deny-answer-aliases" is a little-used feature intended to h…7.5
- CVE-2018-5742While backporting a feature for a newer branch of BIND9, Red…7.5
- CVE-2018-5743By design, BIND is intended to limit the number of TCP clien…7.5
- CVE-2018-5744A failure to free memory can occur when processing messages …7.5
- CVE-2018-5745"managed-keys" is a feature which allows a BIND resolver to …4.9
- CVE-2018-5746Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2018-5747In Long Range Zip (aka lrzip) 0.631, there is a use-after-fr…5.5
Are you affected by CVE-2018-5741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
