CVE-2018-5743
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
Affected (78)
Products: F5: Big Ip Local Traffic Manager, Big Ip Application Acceleration Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Access Policy Manager, Big Ip Application Security Manager, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Webaccelerator, Big Ip Policy Enforcement Manager, Enterprise Manager, Big Iq Centralized Management, Iworkflow, Big Ip Domain Name System · Isc: Bind
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.1.1 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.0.0 to 5.4.0 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.2 to 11.6.5 |
References (6)
Source: security-officer@isc.org
Source: security-officer@isc.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.