CVE-2019-6477
HIGHBIND 9.11.7-9.11.11 - Uncontrolled Resource Consumption via TCP Pipelining
Title source: llmDescription
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).
References (8)
Core 8
Core References
Third Party Advisory x_refsource_confirm
https://kb.isc.org/docs/cve-2019-6477
Third Party Advisory x_refsource_confirm
https://www.synology.com/security/advisory/Synology_SA_19_39
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGURMGQHX45KR4QDRCSUQHODUFOGNGAN/
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K15840535?utm_source=f5support&%3Butm_medium=RSS
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3DEMNZMKR57VQJCG5ZN55ZGTQRL2TFQ/
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2020/dsa-4689
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
Scores
CVSS v3
7.5
EPSS
0.0568
EPSS Percentile
90.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (7)
fedoraproject/fedora
30
fedoraproject/fedora
31
isc/bind
9.11.5 s6
isc/bind
9.11.6 p1 (2 CPE variants)
isc/bind
9.11.12 s1
isc/bind
9.12.4 p1 (2 CPE variants)
isc/bind
9.11.7 - 9.11.12
Published
Nov 26, 2019
Tracked Since
Feb 18, 2026