"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
Source: MITRE
Published: 2019-10-09
Updated: 2019-11-06
Type: CWE-327
Base Score: 3.5
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 6.8
Severity: LOW
Base Score: 4.9
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.2
Severity: MEDIUM
OR
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* versions from 9.9.0 to 9.10.7 (inclusive)
cpe:2.3:a:isc:bind:9.9.3:s1:*:*:*:supported_preview:*:*
cpe:2.3:a:isc:bind:9.10.7:-:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.8:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* versions from 9.11.0 to 9.11.4 (inclusive)
cpe:2.3:a:isc:bind:9.11.5:-:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.5:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.5:s3:*:*:*:supported_preview:*:*
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* versions from 9.12.0 to 9.12.2 (inclusive)
cpe:2.3:a:isc:bind:9.12.3:-:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.12.3:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* versions from 9.13.0 to 9.13.6 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
144003 | NewStart CGSL CORE 5.05 / MAIN 5.05 : bind Multiple Vulnerabilities (NS-SA-2020-0095) | Nessus | NewStart CGSL Local Security Checks | medium |
143897 | NewStart CGSL CORE 5.04 / MAIN 5.04 : bind Multiple Vulnerabilities (NS-SA-2020-0063) | Nessus | NewStart CGSL Local Security Checks | medium |
138043 | Amazon Linux 2 : bind (ALAS-2020-1441) | Nessus | Amazon Linux Local Security Checks | medium |
135801 | Scientific Linux Security Update : bind on SL7.x x86_64 (20200407) | Nessus | Scientific Linux Local Security Checks | medium |
135622 | EulerOS Virtualization 3.0.2.2 : bind (EulerOS-SA-2020-1460) | Nessus | Huawei Local Security Checks | medium |
135328 | CentOS 7 : bind (CESA-2020:1061) | Nessus | CentOS Local Security Checks | medium |
135069 | RHEL 7 : bind (RHSA-2020:1061) | Nessus | Red Hat Local Security Checks | medium |
134492 | EulerOS Virtualization for ARM 64 3.0.2.0 : bind (EulerOS-SA-2020-1203) | Nessus | Huawei Local Security Checks | medium |
132274 | EulerOS 2.0 SP3 : bind (EulerOS-SA-2019-2557) | Nessus | Huawei Local Security Checks | medium |
131607 | EulerOS 2.0 SP2 : bind (EulerOS-SA-2019-2453) | Nessus | Huawei Local Security Checks | medium |
131486 | EulerOS Virtualization for ARM 64 3.0.3.0 : bind (EulerOS-SA-2019-2321) | Nessus | Huawei Local Security Checks | medium |
130837 | EulerOS 2.0 SP5 : bind (EulerOS-SA-2019-2128) | Nessus | Huawei Local Security Checks | medium |
130551 | RHEL 8 : bind (RHSA-2019:3552) | Nessus | Red Hat Local Security Checks | medium |
129526 | SUSE SLED12 / SLES12 Security Update : bind (SUSE-SU-2019:2502-1) | Nessus | SuSE Local Security Checks | medium |
128191 | EulerOS 2.0 SP8 : bind (EulerOS-SA-2019-1822) | Nessus | Huawei Local Security Checks | medium |
125808 | openSUSE Security Update : bind (openSUSE-2019-1533) | Nessus | SuSE Local Security Checks | medium |
125807 | openSUSE Security Update : bind (openSUSE-2019-1532) | Nessus | SuSE Local Security Checks | medium |
125799 | SUSE SLES12 Security Update : bind (SUSE-SU-2019:1449-1) | Nessus | SuSE Local Security Checks | medium |
125759 | SUSE SLES11 Security Update : bind (SUSE-SU-2019:14074-1) | Nessus | SuSE Local Security Checks | medium |
125703 | SUSE SLED15 / SLES15 Security Update : bind (SUSE-SU-2019:1407-1) | Nessus | SuSE Local Security Checks | medium |
124722 | Debian DSA-4440-1 : bind9 - security update | Nessus | Debian Local Security Checks | medium |
122554 | F5 Networks BIG-IP : BIND vulnerability (K25244852) | Nessus | F5 Networks Local Security Checks | low |
122513 | Debian DLA-1697-1 : bind9 security updat | Nessus | Debian Local Security Checks | medium |
122506 | ISC BIND Assertion Failure Vulnerability | Nessus | DNS | low |
122399 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : Bind vulnerabilities (USN-3893-1) | Nessus | Ubuntu Local Security Checks | medium |