PT-2018-1822 · Isc+7 · Bind+7

Jayachandran Palanisamy

·

Publicado

2018-01-16

·

Atualizado

2024-06-15

·

CVE-2017-3145

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: BIND versions 9.0.0 through 9.8.x BIND versions 9.9.0 through 9.9.11 BIND versions 9.10.0 through 9.10.6 BIND versions 9.11.0 through 9.11.2 BIND versions 9.9.3-S1 through 9.9.11-S1 BIND versions 9.10.5-S1 through 9.10.6-S1 BIND versions 9.12.0a1 through 9.12.0rc1
Description: The issue is related to improper sequencing of cleanup operations on upstream recursion fetch contexts in BIND, leading to a use-after-free error. This can trigger an assertion failure and crash in named. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations: For BIND versions 9.0.0 through 9.8.x, update to a version outside of this range to resolve the issue. For BIND versions 9.9.0 through 9.9.11, update to a version outside of this range to resolve the issue. For BIND versions 9.10.0 through 9.10.6, update to a version outside of this range to resolve the issue. For BIND versions 9.11.0 through 9.11.2, update to a version outside of this range to resolve the issue. For BIND versions 9.9.3-S1 through 9.9.11-S1, update to a version outside of this range to resolve the issue. For BIND versions 9.10.5-S1 through 9.10.6-S1, update to a version outside of this range to resolve the issue. For BIND versions 9.12.0a1 through 9.12.0rc1, update to a version outside of this range to resolve the issue.

Correção

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1049
BDU:2018-01422
CESA-2018_0101
CESA-2018_0102
CVE-2017-3145
DLA-1255-1
DSA-4089-1
MGASA-2018-0092
MGASA-2018-0093
OPENSUSE-SU-2018_0323-1
OPENSUSE-SU-2024:10650-1
RHSA-2018:0101
RHSA-2018:0102
RHSA-2018:0487
RHSA-2018:0488
RHSA-2018_0101
RHSA-2018_0102
SUSE-SU-2018:0303-1
SUSE-SU-2018:0362-1
SUSE-SU-2018_0303-1
SUSE-SU-2018_0362-1
USN-3535-1
USN-3535-2

Produtos afetados

Alt Linux
Bind
Bind Server
Centos
Junos
Red Hat
Suse
Ubuntu