CVE-2018-5740

    Dashboard / Vulnerabilities / CVE-2018-5740

    CVE-2018-5740

    Published: 16 Jan 2019Last Modified: 7 Aug 2026

    Summary:

    Details: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- e3734ed6d178397992a7f354f75d3a8db785857c

    Affected versions

    v9.9.13rc2
    v9.9.12rc1
    v9.9.12b1
    v9.9.11rc1
    v9.9.11b1
    v9.9.10
    v9.9.10rc3
    v9.9.10rc2
    v9.9.10rc1
    v9.9.10b1
    v9.9.9
    v9.9.9rc1
    v9.9.9b2
    v9.9.9b1
    v9.9.8
    v9.9.8rc1
    v9.9.8b1
    v9.9.7
    v9.9.7rc2
    v9.9.7rc1
    v9.9.7b1
    v9.9.6
    v9.9.6rc2
    v9.9.6rc1
    v9.9.6b2
    v9.9.6b1
    v9.9.5
    v9.9.5rc2
    v9.9.5rc1
    v9.9.5b1
    v9.9.4
    v9.9.4rc2
    v9.9.4b1
    v9.9.3
    v9.9.3rc2
    v9.9.3rc1
    v9.9.3b2
    v9.9.3b1
    v9.9.2rc1
    v9.9.2b1
    v9.9.1
    v9.9.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High