CVE-2018-5745
bind9 - security update
Description
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
How to fix CVE-2018-5745
To remediate CVE-2018-5745, upgrade the affected package to a fixed version below.
- —upgrade to 9.12.3_p4-r0 or later
- —upgrade to 1:9.11.5.P4+dfsg-1 or later
- —upgrade to 1:9.9.5.dfsg-9+deb8u17 or later
Is CVE-2018-5745 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 9.12.3_p4-r0
- from 0, < 1:9.11.5.P4+dfsg-1
- from 0, < 1:9.9.5.dfsg-9+deb8u17
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |