« Volver al listado

CVE-2018-5744

Estado: ModificadaAlta (7.5)—

A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-5744",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security-officer@isc.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-officer@isc.org",
      "affectedData": [
        {
          "vendor": "ISC",
          "product": "BIND 9",
          "versions": [
            {
              "status": "affected",
              "version": "BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected."
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-09T16:15:13.907",
  "references": [
    {
      "url": "https://kb.isc.org/docs/cve-2018-5744",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-officer@isc.org"
    },
    {
      "url": "https://kb.isc.org/docs/cve-2018-5744",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-772"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected."
    },
    {
      "lang": "es",
      "value": "Se puede presentar un fallo al liberar memoria cuando se procesan mensajes que tienen una combinación específica de opciones EDNS. Las versiones afectadas son: BIND 9.10.7 hasta 9.10.8-P1, 9.11.3 hasta 9.11.5-P1, 9.12.0 hasta 9.12.3-P1, y las versiones 9.10.7-S1 hasta 9.11.5-S3 de BIND 9 Supported Preview Edition. Las versiones 9.13.0 hasta 9.13.6 de la rama de desarrollo 9.13 también están afectadas."
    }
  ],
  "lastModified": "2026-06-17T02:00:42.413",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36D308B6-4ED9-489D-A67F-959B52DB7CAD",
              "versionEndExcluding": "9.10.8",
              "versionStartIncluding": "9.10.7"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A1A72B8-2E02-41EF-A24E-77D6322DBEFF",
              "versionEndExcluding": "9.11.5",
              "versionStartIncluding": "9.11.3"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1B4653B-EE51-40D1-8845-FF2873C6D135",
              "versionEndExcluding": "9.12.3",
              "versionStartIncluding": "9.12.0"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F1DDC1A-7611-4242-9F5B-DC11B1DDE7A7",
              "versionEndExcluding": "9.13.6",
              "versionStartIncluding": "9.13.0"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6243685F-1E5B-4FF6-AE1B-44798032FBA6"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.10.8:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ABCD105-A5E8-41AF-AE84-622543953449"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.10.8:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58D8814F-07FC-42A8-99EF-CD84AADEDC57"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.10.8:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2EE4D37-E5E9-4602-AC6B-5637E4483530"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.10.8:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DAC3F97-D828-474C-80D7-6D23A86372BF"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.11.5:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10C5868-A7C3-48A5-BDE9-1CE0FC0F515F"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.11.5:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB1A7C62-4700-4DE1-B0C2-16D94D0FE4C2"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.11.5:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F066C19-68DB-44BE-8757-ACD794BA1A4B"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AA16E51-819C-4A1B-B66E-1C60C1782C0D"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.12.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F59BE241-48B6-47CC-8500-96A8A1E67954"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.12.3:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B12AA91-F54B-4C97-9168-8E276F16F22B"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.12.3:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9759042-7B05-476D-8D2E-05BE221FFA64"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-officer@isc.org"
}