Back

HIGH

Limiting simultaneous TCP clients was ineffective

Published Oct 9, 2019

Description

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.

Affected products

Remediation

Vendor solution

Upgrade to a version of BIND containing a fix for the ineffective limits.

+ BIND 9.11.6-P1 + BIND 9.12.4-P1 + BIND 9.14.1

BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.

+ BIND 9.11.5-S6 + BIND 9.11.6-S1

Red Hat statement

This bind flaw can be exploited by a remote attacker (AV:N) by opening large number of simultaneous TCP client connections with the server. No special exploit code is required apart from the ability to open large number of TCP connections simultaneously either from one attacker machine or via some distributed attacker network (AC:L and PR:L). No user interaction is required from the server side (UI:N). The attacker can cause denial of service (A:H) by exhausting the file descriptor pool which named has access to. Also in cases where named process is not limited by OS-enforced per-process limits, this could cause exhaustion of available free file descriptors on the system running the named server causing denial of service for other processes running on that machine (S:C).

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Oct 9, 2019
Updated Sep 17, 2024
Reserved Jan 17, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 24, 2019