← Back

CVE-2019-6470

nvd nist
Published: Nov 1, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later, or BIND versions with specific bug fixes backported to them. ISC does not have access to comprehensive version lists for all repackagings of dhcpd that are vulnerable. In particular, builds from other vendors may also be affected. Operators are advised to consult their vendor documentation.

Affected (51)

1 product
Dhcpd
17 products
1 product
Leap
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.4.1
Configuration B
48 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Version 7.0
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 8.0
Redhat
Version 8.1_aarch64
Version 8.2_aarch64
Version 8.4_aarch64
Version 8.6_aarch64
Version 8.8_aarch64
Redhat
Version 7.0
Version 8.0
Redhat
Version 8.1_s390x
Version 8.2_s390x
Version 8.4_s390x
Version 8.6_s390x
Version 8.8_s390x
Version 7.0
Redhat
Version 7.0
Version 8.0
Redhat
Version 8.1_ppc64le
Version 8.2_ppc64le
Version 8.4_ppc64le
Version 8.6_ppc64le
Version 8.8_ppc64le
Version 7.0
Version 7.0
Redhat
Version 8.2
Version 8.4
Version 8.6
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 7.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.1

References (10)

Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
ExploitMailing ListThird Party Advisory
Source: security-officer@isc.org
Mailing ListThird Party Advisory
Source: security-officer@isc.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.