Sploitus

CVE-2018-5743

No indexed exploits for CVE-2018-5743 yet

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.

f5 Big-ip Local Traffic Manager
≤ 11.6.5, 12.1.4, 13.1.1, 14.1.0, 15.0.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
6.5% (93th percentile)
Weakness
CWE-770
NVD status
Modified
Published
2019-10-09

Fix

Upgrade to a version of BIND containing a fix for the ineffective limits. + BIND 9.11.6-P1 + BIND 9.12.4-P1 + BIND 9.14.1 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. + BIND 9.11.5-S6 + BIND 9.11.6-S1

CVE-2018-5743 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-5743 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-5743 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.