← Back

CVE-2018-5743

nvd nist
Published: Oct 9, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.

Affected (78)

16 products
Big Ip Local Traffic Manager
Big Ip Advanced Firewall Manager
Big Ip Analytics
Big Ip Access Policy Manager
Big Ip Edge Gateway
Big Ip Fraud Protection Service
Big Ip Global Traffic Manager
Big Ip Link Controller
Big Ip Webaccelerator
Big Ip Policy Enforcement Manager
Enterprise Manager
Big Iq Centralized Management
Iworkflow
Big Ip Domain Name System
1 product
Bind
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.1.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.1.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.1
Version 15.0.0
Configuration G
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration H
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration I
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration J
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.0.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration K
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.1.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration L
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.1.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0
Configuration M
9 vulnerable
Vulnerable SoftwareAffected Versions
Isc
From 9.11.0 to 9.11.6
From 9.12.0 to 9.12.4
From 9.13.0 to 9.13.7
From 9.9.0 to 9.10.8
Version 9.10.8 p1
Version 9.11.5 s3
Version 9.11.5 s5
Version 9.14.0
Version 9.9.3 s1
Configuration N
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1.1
Configuration O
2 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 5.0.0 to 5.4.0
From 6.0.0 to 6.1.0
Configuration P
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.3.0
Configuration Q
5 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.5.2 to 11.6.5
From 12.1.0 to 12.1.4
From 13.1.0 to 13.1.1
From 14.0.0 to 14.1.0
Version 15.0.0

References (6)

Source: security-officer@isc.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.