{"id":"CVE-2019-6467","details":"A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-\u003e 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.","modified":"2026-07-08T20:57:47.222472Z","published":"2019-10-09T16:15:16.593Z","related":["CGA-5wfh-w6x9-v5rc"],"references":[{"type":"ADVISORY","url":"https://kb.isc.org/docs/cve-2019-6467"},{"type":"ADVISORY","url":"https://www.synology.com/security/advisory/Synology_SA_19_20"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/isc-projects/bind9","events":[{"introduced":"71a40862c0be867999867cd99e21c2266a5e452b"},{"last_affected":"a953e08740c2d76cd69e3e9515e14544fa3a1dda"},{"introduced":"29b3a7d84240a51099490c0f39ae537f4e0d6a7a"},{"last_affected":"6491691ac4bec0dc59e3eeba2797d65527f3bcd6"},{"introduced":"d1e053ed8dff25af8af241cf5ee2c83bd41a25ad"},{"last_affected":"d1e053ed8dff25af8af241cf5ee2c83bd41a25ad"}],"database_specific":{"cpe":["cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","cpe:2.3:a:isc:bind:9.14.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.12.0"},{"last_affected":"9.12.4"},{"introduced":"9.13.0"},{"last_affected":"9.13.7"},{"introduced":"9.14.0"},{"last_affected":"9.14.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.14.0","v9.14.0","v9.13.7","v9.13.6","v9.13.5","v9.13.4","v9.13.3","v9.13.2","v9.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-6467.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.isc.org/isc-projects/bind9","events":[{"introduced":"71a40862c0be867999867cd99e21c2266a5e452b"},{"last_affected":"a953e08740c2d76cd69e3e9515e14544fa3a1dda"},{"introduced":"29b3a7d84240a51099490c0f39ae537f4e0d6a7a"},{"last_affected":"6491691ac4bec0dc59e3eeba2797d65527f3bcd6"},{"introduced":"d1e053ed8dff25af8af241cf5ee2c83bd41a25ad"},{"last_affected":"d1e053ed8dff25af8af241cf5ee2c83bd41a25ad"}],"database_specific":{"cpe":["cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","cpe:2.3:a:isc:bind:9.14.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.12.0"},{"last_affected":"9.12.4"},{"introduced":"9.13.0"},{"last_affected":"9.13.7"},{"introduced":"9.14.0"},{"last_affected":"9.14.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.14.0","v9.14.0","v9.13.7","v9.13.6","v9.13.5","v9.13.4","v9.13.3","v9.13.2","v9.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-6467.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}