Логотип exploitDog
bind:"GHSA-rqpc-6vjv-w22p" OR bind:"CVE-2018-5740"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-rqpc-6vjv-w22p" OR bind:"CVE-2018-5740"

Количество 14

Количество 14

github логотип

GHSA-rqpc-6vjv-w22p

больше 3 лет назад

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2018-5740

почти 7 лет назад

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2018-5740

больше 7 лет назад

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2018-5740

почти 7 лет назад

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2018-5740

почти 7 лет назад

"deny-answer-aliases" is a little-used feature intended to help recurs ...

CVSS3: 7.5
EPSS: Средний
oracle-oval логотип

ELSA-2018-2571

около 7 лет назад

ELSA-2018-2571: bind security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2018-2570

около 7 лет назад

ELSA-2018-2570: bind security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2019-01628

около 7 лет назад

Уязвимость функции deny-answer-aliases в открытой реализации DNS-сервера BIND, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2019:1533-1

больше 6 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1532-1

больше 6 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1449-1

больше 6 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14074-1

больше 6 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1407-1

больше 6 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2502-1

около 6 лет назад

Security update for bind

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rqpc-6vjv-w22p

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
58%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2018-5740

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
58%
Средний
почти 7 лет назад
redhat логотип
CVE-2018-5740

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
58%
Средний
больше 7 лет назад
nvd логотип
CVE-2018-5740

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

CVSS3: 7.5
58%
Средний
почти 7 лет назад
debian логотип
CVE-2018-5740

"deny-answer-aliases" is a little-used feature intended to help recurs ...

CVSS3: 7.5
58%
Средний
почти 7 лет назад
oracle-oval логотип
ELSA-2018-2571

ELSA-2018-2571: bind security update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2018-2570

ELSA-2018-2570: bind security update (IMPORTANT)

около 7 лет назад
fstec логотип
BDU:2019-01628

Уязвимость функции deny-answer-aliases в открытой реализации DNS-сервера BIND, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
58%
Средний
около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1533-1

Security update for bind

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1532-1

Security update for bind

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1449-1

Security update for bind

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14074-1

Security update for bind

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1407-1

Security update for bind

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2502-1

Security update for bind

около 6 лет назад

Уязвимостей на страницу