PT-2017-15680 · Isc+6 · Bind+6

Published

2017-04-12

·

Updated

2019-10-09

·

CVE-2017-3137

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.9.9-P6 through 9.9.10rc1 BIND versions 9.10.4-P6 through 9.10.5rc1 BIND versions 9.11.0-P3 through 9.11.1rc1 BIND version 9.9.9-S8
Description The issue arises from mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records. This could lead to a situation in which named exits with an assertion failure when processing a response in which records occurred in an unusual order. Attackers can cause a denial of service by sending a response containing CNAME or DNAME resource records with a specially crafted order.
Recommendations For BIND versions 9.9.9-P6 through 9.9.10rc1, update to a version that fixes the issue. For BIND versions 9.10.4-P6 through 9.10.5rc1, update to a version that fixes the issue. For BIND versions 9.11.0-P3 through 9.11.1rc1, update to a version that fixes the issue. For BIND version 9.9.9-S8, update to a version that fixes the issue. As a temporary workaround, consider restricting the processing of responses with unusual record orders to minimize the risk of exploitation.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1464
CESA-2017_1095
CESA-2017_1105
CVE-2017-3137
DLA-957-1
DSA-3854-1
MGASA-2017-0478
OPENSUSE-SU-2017_1063-1
RHSA-2017:1095
RHSA-2017:1105
RHSA-2017:1582
RHSA-2017:1583
RHSA-2017_1095
RHSA-2017_1105
SUSE-SU-2017:0998-1
SUSE-SU-2017:0999-1
SUSE-SU-2017:1000-1
SUSE-SU-2017:1027-1
SUSE-SU-2017_1027-1
USN-3259-1

Affected Products

Alt Linux
Bind
Bind Server
Centos
Red Hat
Suse
Ubuntu