Number: AV18-154
Date: 21 September 2018
Purpose
The purpose of this advisory is to bring attention to a security advisory recently released by the Internet Systems Consortium (ISC).
Assessment
The Internet Systems Consortium (ISC) has released a security advisory that addresses a vulnerability affecting multiple versions of ISC Berkeley Internet Name Domain (BIND). A successful exploitation of this vulnerability by an authenticated remote attacker may allow the modification of records on the server for versions of BIND that contain the krb-5-subdomain and ms-subdomain update policies.
Affected product:
All versions of BIND 9 prior to maintenance releases, BIND 9.11.5 and 9.12.3.
CVE Reference: CVE-2018-5741
Suggested action
CCIRC recommends that system administrators review the ISC advisory and apply the solution on affected products accordingly.