Vulnerability record · CVE-2018-5736 · published 16 January 2019
CVE-2018-5736: Isc bind vulnerability
Isc · Bind
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
Description
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. Affects BIND 9.12.0 and 9.12.1.
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104386 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040941 | Third Party AdvisoryVDB Entry |
| https://kb.isc.org/docs/aa-01602 | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20180926-0004/ | Third Party Advisory |
| http://www.securityfocus.com/bid/104386 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040941 | Third Party AdvisoryVDB Entry |
| https://kb.isc.org/docs/aa-01602 | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20180926-0004/ | Third Party Advisory |
Track CVE-2018-5736 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-5736), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.