QID 15136
Date Published: 2023-05-29
QID 15136: ISC BIND Multiple Vulnerabilities
The DNSSEC verification code for the EdDSA algorithm leaks memory when there is a signature length mismatch.
Affected versions:
BIND 9.9.12 - 9.9.13
BIND 9.10.7 - 9.10.8
BIND 9.11.3 - 9.16.32
BIND 9.18.0 - 9.18.6
BIND 9.19.0 - 9.19.4
BIND 9.11.4-S1 - 9.11.37-S1
BIND 9.16.8-S1 - 9.16.32-S1
Patched Versions:
BIND 9.16.33
BIND 9.18.7
BIND 9.19.5
BIND 9.16.33-S1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successfully exploitation could affects integrity, availability, confidentiality
Solution
Customers are advised to upgrade to the patched version 9.16.33, 9.18.7, 9.19.5, 9.16.33-S1 or latest release of ISC BIND.
Workaround:
Disable the following algorithms in your configuration using the disable-algorithms option: ED25519, ED448. Note that this causes zones signed with these algorithms to be treated as insecure.
Workaround:
Disable the following algorithms in your configuration using the disable-algorithms option: ED25519, ED448. Note that this causes zones signed with these algorithms to be treated as insecure.
Vendor References
- CVE-2022-38178 -
kb.isc.org/v1/docs/cve-2022-38178
CVEs related to QID 15136
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-38178 |
|