CVE-2019-6477
Last modified
CVE-2019-6477 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. EPSS estimates a 4.02% chance of exploitation in the next 30 days.
Description
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Isc | Bind | >= 9.11.7, <= 9.11.12 | — |
| Isc | Bind | >= 9.14.1, <= 9.14.7 | — |
| Isc | Bind | >= 9.15.0, <= 9.15.5 | — |
| Isc | Bind | 9.11.5 | S6 |
| Isc | Bind | 9.11.6 | P1 |
| Isc | Bind | 9.11.12 | S1 |
| Isc | Bind | 9.12.4 | P1 |
| Fedoraproject | Fedora | 30 | — |
| Fedoraproject | Fedora | 31 | — |
References
- https://kb.isc.org/docs/cve-2019-6477Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_39Third Party Advisory
- https://kb.isc.org/docs/cve-2019-6477Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_39Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6477?
How severe is CVE-2019-6477?
How do I fix CVE-2019-6477?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6471A race condition which may occur when discarding malformed p…5.9
- CVE-2019-6472A packet containing a malformed DUID can cause the Kea DHCPv…6.5
- CVE-2019-6473An invalid hostname option can trigger an assertion failure …6.5
- CVE-2019-6474A missing check on incoming client requests can be exploited…6.5
- CVE-2019-6475Mirror zones are a BIND feature allowing recursive servers t…7.5
- CVE-2019-6476A defect in code added to support QNAME minimization can cau…7.5
- CVE-2019-6478Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2019-6479Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: T…
- CVE-2019-6481Abine Blur 7.8.2431 allows remote attackers to conduct "Seco…
- CVE-2019-6485Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 befor…
- CVE-2019-6486Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 a…
- CVE-2019-6487TP-Link WDR Series devices through firmware v3 (such as TL-W…
Are you affected by CVE-2019-6477?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
