PT-2017-15681 · Isc+4 · Bind+4

Mike Lalumiere

·

Publicado

2017-04-12

·

Atualizado

2019-10-09

·

CVE-2017-3138

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND 9.9.9 through 9.9.9-P7 BIND 9.9.10b1 through 9.9.10rc2 BIND 9.10.4 through 9.10.4-P7 BIND 9.10.5b1 through 9.10.5rc2 BIND 9.11.0 through 9.11.0-P4 BIND 9.11.1b1 through 9.11.1rc2 BIND 9.9.9-S1 through 9.9.9-S9
Description The issue arises from a regression in a recent feature change, allowing attackers to cause a denial of service by sending a null command string over a control channel to the named server process. This can result in the server exiting with a REQUIRE assertion failure.
Recommendations For BIND 9.9.9 through 9.9.9-P7, update to a version outside of this range to resolve the issue. For BIND 9.9.10b1 through 9.9.10rc2, update to a version outside of this range to resolve the issue. For BIND 9.10.4 through 9.10.4-P7, update to a version outside of this range to resolve the issue. For BIND 9.10.5b1 through 9.10.5rc2, update to a version outside of this range to resolve the issue. For BIND 9.11.0 through 9.11.0-P4, update to a version outside of this range to resolve the issue. For BIND 9.11.1b1 through 9.11.1rc2, update to a version outside of this range to resolve the issue. For BIND 9.9.9-S1 through 9.9.9-S9, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the control channel to minimize the risk of exploitation.

Correção

DoS

Assertion Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1464
CVE-2017-3138
DLA-957-1
DSA-3854-1
MGASA-2017-0478
OPENSUSE-SU-2017_1063-1
SUSE-SU-2017:0998-1
SUSE-SU-2017:0999-1
SUSE-SU-2017:1000-1
USN-3259-1

Produtos afetados

Alt Linux
Bind
Bind Server
Suse
Ubuntu