PT-2017-15678 · Isc+6 · Bind+6

Published

2017-01-12

·

Updated

2024-06-15

·

CVE-2017-3135

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.8.8, 9.9.3 through 9.9.9-S7, 9.9.3 through 9.9.9-P5, 9.9.10b1, 9.10.0 through 9.10.4-P5, 9.10.5b1, 9.11.0 through 9.11.0-P2, 9.11.1b1
Description The issue arises when using both DNS64 and RPZ to rewrite query responses, leading to inconsistent query processing states. This can result in either an INSIST assertion failure or an attempt to read through a NULL pointer, causing a denial of service.
Recommendations For versions 9.8.8, 9.9.3 through 9.9.9-S7, 9.9.3 through 9.9.9-P5, 9.9.10b1, 9.10.0 through 9.10.4-P5, 9.10.5b1, 9.11.0 through 9.11.0-P2, 9.11.1b1, consider disabling the use of DNS64 and RPZ together until a patch is available. As a temporary workaround, restrict the use of RPZ to minimize the risk of exploitation. Avoid using DNS64 in conjunction with RPZ to rewrite query responses until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1027
ALT-PU-2017-1143
CESA-2017_0276
CVE-2017-3135
DLA-843-1
DSA-3795-1
MGASA-2017-0478
OPENSUSE-SU-2024:10650-1
RHSA-2017:0276
RHSA-2017_0276
SUSE-SU-2017:0594-1
SUSE-SU-2017:0595-1
SUSE-SU-2017:0596-1
SUSE-SU-2017_0594-1
SUSE-SU-2017_0595-1
SUSE-SU-2017_0596-1
USN-3201-1

Affected Products

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu