CVE-2019-6467
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/10/2019
Last modified:
18/12/2019
Description
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | 9.12.0 (including) | 9.12.4 (including) |
| cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | 9.13.0 (including) | 9.13.7 (including) |
| cpe:2.3:a:isc:bind:9.14.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



