← back
CVE-2019-6476medium

An error in QNAME minimization code can cause BIND to exit with an assertion failure

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 2.9%
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
ISC · BIND 9