PT-2017-15684 · Isc+7 · Bind+7

Clã©Ment Berthaux

·

Publicado

2017-06-29

·

Atualizado

2024-06-15

·

CVE-2017-3142

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BIND versions 9.4.0 through 9.8.8 BIND versions 9.9.0 through 9.9.10-P1 BIND versions 9.10.0 through 9.10.5-P1 BIND versions 9.11.0 through 9.11.1-P1 BIND versions 9.9.3-S1 through 9.9.10-S2 BIND versions 9.10.5-S1 through 9.10.5-S2
Description The issue allows an attacker who can send and receive messages to an authoritative DNS server and has knowledge of a valid TSIG key name to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. This could result in providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. An attacker could exploit this by sending specially crafted data to bypass TSIG authentication and manipulate the server into accepting an unauthorized dynamic update.
Recommendations For BIND versions 9.4.0 through 9.8.8, update to a version outside of this range to mitigate the risk. For BIND versions 9.9.0 through 9.9.10-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.10.0 through 9.10.5-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.11.0 through 9.11.1-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.9.3-S1 through 9.9.10-S2, update to a version outside of this range to mitigate the risk. For BIND versions 9.10.5-S1 through 9.10.5-S2, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the TSIG key name and implementing additional ACL protection to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1966
CESA-2017_1679
CESA-2017_1680
CVE-2017-3142
DLA-1025-1
DSA-3904-1
DSA-3904-2
MGASA-2017-0478
OPENSUSE-SU-2017_1809-1
OPENSUSE-SU-2024:10650-1
RHSA-2017:1679
RHSA-2017:1680
RHSA-2017_1679
RHSA-2017_1680
SUSE-SU-2017:1736-1
SUSE-SU-2017:1737-1
SUSE-SU-2017:1738-1
SUSE-SU-2017_1736-1
SUSE-SU-2017_1737-1
SUSE-SU-2017_1738-1
USN-3346-1
USN-3346-2
USN-3346-3

Produtos afetados

Alt Linux
Bind
Bind Server
Centos
Ibm Aix
Red Hat
Suse
Ubuntu