← Back

CVE-2018-5745

nvd nist
Published: Oct 9, 2019Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.

Affected (12)

Products: Isc: Bind
1 product
Bind
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Isc
From 9.11.0 to 9.11.4
From 9.12.0 to 9.12.2
From 9.13.0 to 9.13.6
From 9.9.0 to 9.10.7
Version 9.10.7
Version 9.10.8 p1
Version 9.11.5
Version 9.11.5 p1
Version 9.11.5 s3
Version 9.12.3
Version 9.12.3 p1
Version 9.9.3 s1

References (4)

Source: security-officer@isc.org
Source: security-officer@isc.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.