CVE-2018-5744 is a denial-of-service vulnerability affecting multiple versions of ISC BIND 9, including specific releases in the 9.10, 9.11, 9.12, and 9.13 development branches. The flaw stems from a memory leak when processing DNS messages containing a particular combination of EDNS options. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, leading to a complete loss of availability for affected DNS servers. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.10.7, < 9.10.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.11.3, < 9.11.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.12.0, < 9.12.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.13.0, < 9.13.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.10.7CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.