CVE-2019-6465: Zone transfer controls for writable DLZ zones were not effective
A flaw was found in Bind. Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable. A client exercising this defect can request and receive a zone transfers of a DLZ even when not permitted to do so by the allow-transfer ACL.
Other sources
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.
— MITRE
ISC BIND could allow a remote attacker to obtain sensitive information, caused by the failure to properly apply controls for zone transfers to Dynamically Loadable Zones (DLZs) if the zones are writable. An attacker could exploit this vulnerability to request and receive a zone transfer of a DLZ even when not permitted to do so by the allow-transfer ACL.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6465?
CVE-2019-6465 is considered a moderate severity vulnerability that can lead to sensitive information exposure.
How do I fix CVE-2019-6465?
To remediate CVE-2019-6465, you should upgrade to BIND version 9.11.5 or 9.12.3 or apply appropriate patches.
What types of systems are affected by CVE-2019-6465?
CVE-2019-6465 affects various versions of ISC BIND and IBM Data Risk Manager that do not have the latest security updates.
Can CVE-2019-6465 be exploited remotely?
Yes, CVE-2019-6465 can be exploited by remote attackers to perform unauthorized zone transfers.
What specific versions of BIND are vulnerable to CVE-2019-6465?
BIND versions prior to 9.11.5 and 9.12.3, as well as several other versions in between, are vulnerable to CVE-2019-6465.