ICS security advisory for BIND

Number: AV18-154
Date: 21 September 2018

Purpose

The purpose of this advisory is to bring attention to a security advisory recently released by the Internet Systems Consortium (ISC).

Assessment

The Internet Systems Consortium (ISC) has released a security advisory that addresses a vulnerability affecting multiple versions of ISC Berkeley Internet Name Domain (BIND). A successful exploitation of this vulnerability by an authenticated remote attacker may allow the modification of records on the server for versions of BIND that contain the krb-5-subdomain and ms-subdomain update policies.

Affected product:
All versions of BIND 9 prior to maintenance releases, BIND 9.11.5 and 9.12.3.

CVE Reference: CVE-2018-5741

Suggested action

CCIRC recommends that system administrators review the ISC advisory and apply the solution on affected products accordingly.

References

https://kb.isc.org/docs/cve-2018-5741

Date modified: