UBUNTU-CVE-2018-5740
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-5740
UBUNTU-CVE-2018-5740
Summary:
Details: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
References: https://ubuntu.com/security/CVE-2018-5740, https://kb.isc.org/article/AA-01639/74/CVE-2018-5740, https://ubuntu.com/security/notices/USN-3769-1, https://ubuntu.com/security/notices/USN-3769-2, https://www.cve.org/CVERecord?id=CVE-2018-5740
Affected packages
Package
Name: bind9
Purl: pkg:deb/ubuntu/bind9@1:9.9.5.dfsg-3ubuntu0.18?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
