cve/2019/CVE-2019-6476.md

18 lines
888 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-6476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6476)
![](https://img.shields.io/static/v1?label=Product&message=BIND%209&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=An%20attacker%20who%20manages%20to%20deliberately%20trigger%20this%20condition%20on%20a%20server%20which%20is%20performing%20recursion%20can%20cause%20named%20to%20exit%2C%20denying%20service%20to%20clients.&color=brighgreen)
### Description
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/bg6cq/bind9