Related Vulnerabilities: CVE-2019-6465  

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable in bind before 9.13.7. A client exercising this defect can request and receive a zone transfer of a DLZ even when not permitted to do so by the allow-transfer ACL.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable in bind before 9.13.7. A client exercising this defect can request and receive a zone transfer of a DLZ even when not permitted to do so by the allow-transfer ACL.

AVG-915 bind 9.13.5-5 9.13.7-1 High Fixed

25 Feb 2019 ASA-201902-25 AVG-915 bind High multiple issues

https://kb.isc.org/docs/cve-2019-6465