Learn about CVE-2019-6467, a vulnerability in BIND 9 affecting versions 9.12.0 to 9.12.4, 9.14.0, and all releases in the 9.13 development branch. Find out the impact, technical details, and mitigation steps.
CVE-2019-6467 is a vulnerability in BIND 9 that can lead to an assertion failure due to a programming error in the nxdomain-redirect feature. This issue affects versions 9.12.0 to 9.12.4, 9.14.0, and all releases in the 9.13 development branch.
Understanding CVE-2019-6467
This CVE involves a specific error in the nxdomain-redirect feature of BIND 9 that can trigger an assertion failure in query.c, potentially impacting the server's functionality.
What is CVE-2019-6467?
The nxdomain-redirect feature in BIND 9 may result in an assertion failure in query.c due to a programming error. This can occur when the alternate namespace used by nxdomain-redirect is a descendant of a locally served zone, affecting server configurations.
The Impact of CVE-2019-6467
An attacker exploiting this vulnerability can cause BIND to exit, denying service to other clients. The affected versions include BIND 9.12.0 to 9.12.4, 9.14.0, and all releases in the 9.13 development branch.
Technical Details of CVE-2019-6467
This section provides detailed technical information about the vulnerability.
Vulnerability Description
A programming error in the nxdomain-redirect feature can lead to an assertion failure in query.c, affecting servers with vulnerable configurations.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be triggered by deliberately exploiting the condition on a server with a vulnerable configuration, causing BIND to exit and deny service to clients.
Mitigation and Prevention
Protecting systems from CVE-2019-6467 involves immediate steps and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Upgrade to the patched releases most closely related to your current version of BIND: