Discover the impact of CVE-2019-6475, a vulnerability in BIND 9 mirror zones allowing attackers to spoof zone data. Learn about affected versions and mitigation steps.
A flaw in mirror zone validity checking can allow zone data to be spoofed.
Understanding CVE-2019-6475
Mirror zones in BIND are a helpful asset for recursive servers, allowing pre-caching of zone data from other servers. However, a vulnerability in mirror zone validity checking can lead to data spoofing.
What is CVE-2019-6475?
Mirror zones in BIND undergo DNSSEC validation before being used in responses. An error in validity checks can enable an attacker to replace trusted zone data with falsified data, affecting BIND versions 9.14.0 to 9.14.6 and 9.15.0 to 9.15.4.
The Impact of CVE-2019-6475
Technical Details of CVE-2019-6475
Vulnerability Description
Mirror zones in BIND can be exploited by attackers to insert falsified data, affecting the integrity of the DNS responses.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates