VendorsISCbind9.12.0
Vulnerabilities

ISC BIND 9.12.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-3145
Improper fetch cleanup sequencing in the resolver can cause named to crash
Published 2019-01-16 · Modified
7.5EPSS 0.279
CVE-2018-5738
Some versions of BIND can improperly permit recursive query service to unauthorized clients
Published 2019-01-16 · Modified
7.5EPSS 0.112
CVE-2018-5737
BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if serve-stale is not enabled.
Published 2019-01-16 · Modified
7.5EPSS 0.104
CVE-2018-5736
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
Published 2019-01-16 · Modified
5.3EPSS 0.180