UBUNTU-CVE-2018-5738

Source
https://ubuntu.com/security/CVE-2018-5738
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-5738.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2018-5738
Related
Published
2018-06-12T00:00:00Z
Modified
2025-01-13T10:21:34Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intended default of "allow-recursion {localhost; localnets;};" if "recursion yes;" is in effect and no values are explicitly set for "allow-query-cache" or "allow-query". However, because of the regression introduced by change #4777, it is possible when "recursion yes;" is in effect and no match list values are provided for "allow-query-cache" or "allow-query" for the setting of "allow-recursion" to inherit a setting of all hosts from the "allow-query" setting default, improperly permitting recursion to all clients. Affects BIND 9.9.12, 9.10.7, 9.11.3, 9.12.0->9.12.1-P2, the development release 9.13.0, and also releases 9.9.12-S1, 9.10.7-S1, 9.11.3-S1, and 9.11.3-S2 from BIND 9 Supported Preview Edition.

References

Affected packages

Ubuntu:18.04:LTS / bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.11.3+dfsg-1ubuntu1.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.11.3+dfsg-1ubuntu1.1

Affected versions

1:9.*

1:9.10.3.dfsg.P4-12.6ubuntu1
1:9.11.2.P1-1ubuntu2
1:9.11.2.P1-1ubuntu3
1:9.11.2.P1-1ubuntu4
1:9.11.2.P1-1ubuntu5
1:9.11.3+dfsg-1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9-doc"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9-host"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9-host-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9utils"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "bind9utils-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "dnsutils"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "dnsutils-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libbind-dev"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libbind-export-dev"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libbind9-160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libbind9-160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libdns-export1100"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libdns-export1100-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libdns-export1100-udeb"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libdns1100"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libdns1100-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libirs-export160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libirs-export160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libirs-export160-udeb"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libirs160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libirs160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisc-export169"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisc-export169-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisc-export169-udeb"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisc169"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisc169-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccc-export160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccc-export160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccc-export160-udeb"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccc160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccc160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccfg-export160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccfg-export160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccfg-export160-udeb"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccfg160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "libisccfg160-dbgsym"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "liblwres160"
        },
        {
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.1",
            "binary_name": "liblwres160-dbgsym"
        }
    ]
}