Lucene search

K
nvd[email protected]NVD:CVE-2018-5738
HistoryJan 16, 2019 - 8:29 p.m.

CVE-2018-5738

2019-01-1620:29:00
CWE-200
web.nvd.nist.gov
2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.6%

Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the “allow-recursion” setting, it SHOULD default to one of the following: none, if “recursion no;” is set in named.conf; a value inherited from the “allow-query-cache” or “allow-query” settings IF “recursion yes;” (the default for that setting) AND match lists are explicitly set for “allow-query-cache” or “allow-query” (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of “allow-recursion {localhost; localnets;};” if “recursion yes;” is in effect and no values are explicitly set for “allow-query-cache” or “allow-query”. However, because of the regression introduced by change #4777, it is possible when “recursion yes;” is in effect and no match list values are provided for “allow-query-cache” or “allow-query” for the setting of “allow-recursion” to inherit a setting of all hosts from the “allow-query” setting default, improperly permitting recursion to all clients. Affects BIND 9.9.12, 9.10.7, 9.11.3, 9.12.0->9.12.1-P2, the development release 9.13.0, and also releases 9.9.12-S1, 9.10.7-S1, 9.11.3-S1, and 9.11.3-S2 from BIND 9 Supported Preview Edition.

Affected configurations

NVD
Node
iscbindMatch9.9.12
OR
iscbindMatch9.9.12s1
OR
iscbindMatch9.10.7
OR
iscbindMatch9.10.7s1
OR
iscbindMatch9.11.3
OR
iscbindMatch9.11.3s1
OR
iscbindMatch9.11.3s2
OR
iscbindMatch9.12.0
OR
iscbindMatch9.12.0a1
OR
iscbindMatch9.12.0b1
OR
iscbindMatch9.12.0b2
OR
iscbindMatch9.12.0rc1
OR
iscbindMatch9.12.0rc3
OR
iscbindMatch9.12.1
OR
iscbindMatch9.12.1p1
OR
iscbindMatch9.12.1p2
OR
iscbindMatch9.13.0
Node
canonicalubuntu_linuxMatch18.04lts

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.2 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.6%