QID 15158

Date Published: 2024-03-11

QID 15158: ISC BIND Security Update (CVE-2023-5517)

ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.

CVE-2023-5517: A flaw in query-handling code can cause "named" to exit prematurely with an assertion failure when: "nxdomain-redirect domain;" is configured, and the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response.

Affected versions:
BIND 9.12.0 to 9.16.45
BIND 9.18.0 to 9.18.21
BIND 9.19.0 to 9.19.19
BIND Supported Preview Edition 9.16.8-S1 to 9.16.45-S1
BIND Supported Preview Edition 9.18.11-S1 to 9.18.21-S1

Patched Versions:
BIND 9.16.48
BIND 9.18.24
BIND 9.19.21
BIND Supported Preview Edition 9.16.48-S1
BIND Supported Preview Edition 9.18.24-S1

QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service using the banner.

Note: This QID has been marked as potential as this vulnerability has a workaround, that cannot be detected through unauthenticated detection.

Successful exploitation of this vulnerability may compromise Confidentiality, Integrity, and Availability of data.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade to the patched version latest release of CVE-2023-5517
    Workaround:
    Disabling the nxdomain-redirect feature makes the faulty code path impossible to reach, preventing this flaw from being exploitable.
    Vendor References

    CVEs related to QID 15158

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-5517 URL Logo kb.isc.org/docs/cve-2023-5517