CVE编号
CVE-2018-5740利用情况
暂无补丁情况
官方补丁披露时间
2019-01-17漏洞描述
在包含“ deny-answer-aliases”功能的绑定版本中发现了拒绝服务漏洞。此漏洞可能允许远程攻击者以名义触发INSIST断言,从而导致进程终止和服务条件拒绝。解决建议
厂商已发布漏洞修复程序,请及时关注更新:https://kb.isc.org/article/AA-01639/0
参考链接 |
|
---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00026.html | |
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00027.html | |
http://www.securityfocus.com/bid/105055 | |
http://www.securitytracker.com/id/1041436 | |
https://access.redhat.com/errata/RHSA-2018:2570 | |
https://access.redhat.com/errata/RHSA-2018:2571 | |
https://kb.isc.org/docs/aa-01639 | |
https://lists.debian.org/debian-lts-announce/2018/08/msg00033.html | |
https://lists.debian.org/debian-lts-announce/2021/11/msg00001.html | |
https://security.gentoo.org/glsa/201903-13 | |
https://security.netapp.com/advisory/ntap-20180926-0003/ | |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-... | |
https://usn.ubuntu.com/3769-1/ | |
https://usn.ubuntu.com/3769-2/ |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | isc | bind | * |
From (including) 9.10.0 |
Up to (excluding) 9.10.8 |
||||
运行在以下环境 | |||||||||
应用 | isc | bind | * |
From (including) 9.11.0 |
Up to (excluding) 9.11.4 |
||||
运行在以下环境 | |||||||||
应用 | isc | bind | * |
From (including) 9.12.0 |
Up to (excluding) 9.12.2 |
||||
运行在以下环境 | |||||||||
应用 | isc | bind | * |
From (including) 9.13.0 |
Up to (excluding) 9.13.2 |
||||
运行在以下环境 | |||||||||
应用 | isc | bind | * |
From (including) 9.7.0 |
Up to (excluding) 9.8.8 |
||||
运行在以下环境 | |||||||||
应用 | isc | bind | * |
From (including) 9.9.0 |
Up to (excluding) 9.9.13 |
||||
运行在以下环境 | |||||||||
应用 | netapp | data_ontap_edge | - | - | |||||
运行在以下环境 | |||||||||
系统 | alpine_3.10 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.11 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.12 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.13 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.14 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.15 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.5 | bind | * |
Up to (excluding) 9.10.8_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.6 | bind | * |
Up to (excluding) 9.11.4_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.7 | bind | * |
Up to (excluding) 9.11.4_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.8 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.9 | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_edge | bind | * |
Up to (excluding) 9.12.2_p1-r0 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_2 | bind | * |
Up to (excluding) 9.9.4-61.amzn2.1.1 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | bind | * |
Up to (excluding) 9.8.2-0.68.rc1.58.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_6 | bind | * |
Up to (excluding) 9.8.2-0.68.rc1.el6_10.1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_7 | bind | * |
Up to (excluding) 9.9.4-61.el7_5.1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | bind | * |
Up to (excluding) 1:9.9.5.dfsg-9+deb8u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | bind | * |
Up to (excluding) 1:9.10.3.dfsg.P4-12.3+deb9u10 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_27 | bind | * |
Up to (excluding) 9.11.4-2.P1.fc27 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_28 | bind | * |
Up to (excluding) 9.11.4-5.P1.fc28 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.0 | bind | * |
Up to (excluding) 9.11.2-lp151.11.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.1 | bind | * |
Up to (excluding) 9.11.2-lp151.11.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_42.3 | bind | * |
Up to (excluding) 9.9.9P1-56.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_6 | bind | * |
Up to (excluding) 9.8.2-0.68.rc1.el6_10.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_7 | bind | * |
Up to (excluding) 9.9.4-61.el7_5.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP4 | bind | * |
Up to (excluding) 9.11.2-3.10.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04 | bind | * |
Up to (excluding) 1:9.9.5.dfsg-3ubuntu0.18 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04 | bind | * |
Up to (excluding) 1:9.10.3.dfsg.P4-8ubuntu1.11 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04 | bind | * |
Up to (excluding) 1:9.11.3+dfsg-1ubuntu1.2 |
|||||
- 攻击路径 远程
- 攻击复杂度 复杂
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 100
还没有评论,来说两句吧...