A vulnerability was found in "deny-answer-aliases" feature of the Internet Systems Consortium (ISC) BIND software. A remote attacker could send a specially crafted query to trigger an assertion failure. Only those servers with "deny-answer-aliases" feature explicitly enabled are affected.
Successful exploitation could lead to a denial of service condition on an affected system.
ISC has released the following patches to solve the problems:
This link will open in a new windowhttp://www.isc.org/downloads
Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
This link will open in a new windowhttps://kb.isc.org/article/AA-01639/0
This link will open in a new windowhttps://www.hkcert.org/my_url/en/alert/18080901
This link will open in a new windowhttps://www.us-cert.gov/ncas/current-activity/2018/08/08/ISC-Releases-Security-Advisory-BIND
This link will open in a new windowhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5740