Back

HIGH

A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named

Published Jan 16, 2019

Description

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

Affected products

Remediation

Vendor solution

Most operators will not need to make any changes unless they are using the "deny-answer-aliases" feature (which is described in the BIND 9 Adminstrator Reference Manual section 6.2.) "deny-answer-aliases" is off by default; only configurations which explicitly enable it can be affected by this defect.

If you are using "deny-answer-aliases", upgrade to the patched release most closely related to your current version of BIND.

9.9.13-P1 9.10.8-P1 9.11.4-P1 9.12.2-P1

BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.

9.11.3-S3

Red Hat statement

The "deny-answer-aliases" configuration option is not enabled in default configurations of bind. Upstream states that this option is very rarely used. As such, if customers have not specifically enabled this option in configurations, the risk should be mitigated.

Red Hat mitigation

Disabling the "deny-answer-aliases" configuration option should prevent exploitation.

Metrics

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jan 16, 2019
Updated Sep 16, 2024
Reserved Jan 17, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 8, 2018