QID 15156
Date Published: 2024-03-11
QID 15156: ISC BIND Security Update (CVE-2023-5679)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
Affected versions:
BIND 9.16.12 - 9.16.45
BIND 9.18.0 - 9.18.21
BIND 9.19.0 - 9.19.19
BIND Supported Preview Edition 9.16.12-S1 - 9.16.45-S1
BIND Supported Preview Edition 9.18.11-S1 - 9.18.21-S1
Patched Versions:
BIND 9.16.48
BIND 9.18.24
BIND 9.19.21
BIND Supported Preview Edition 9.16.48-S1
BIND Supported Preview Edition 9.18.24-S1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service using banner.
By querying a DNS64-enabled resolver for domain names triggering serve-stale, an attacker can cause named to crash with an assertion failure.
Solution
Customers are advised to upgrade to the patched version latest release of CVE-2023-5679.
Workaround:
Disabling serve-stale (with stale-cache-enable no; and stale-answer-enable no;) and/or disabling dns64 makes the faulty code path impossible to reach, preventing this flaw from being exploitable.
Workaround:
Disabling serve-stale (with stale-cache-enable no; and stale-answer-enable no;) and/or disabling dns64 makes the faulty code path impossible to reach, preventing this flaw from being exploitable.
Vendor References
- CVE-2023-5679 -
kb.isc.org/docs/cve-2023-5679
CVEs related to QID 15156
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-5679 |
|