PT-2017-15681 · Isc+4 · Bind+4

Mike Lalumiere

·

Published

2017-04-12

·

Updated

2019-10-09

·

CVE-2017-3138

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND 9.9.9 through 9.9.9-P7 BIND 9.9.10b1 through 9.9.10rc2 BIND 9.10.4 through 9.10.4-P7 BIND 9.10.5b1 through 9.10.5rc2 BIND 9.11.0 through 9.11.0-P4 BIND 9.11.1b1 through 9.11.1rc2 BIND 9.9.9-S1 through 9.9.9-S9
Description The issue arises from a regression in a recent feature change, allowing attackers to cause a denial of service by sending a null command string over a control channel to the named server process. This can result in the server exiting with a REQUIRE assertion failure.
Recommendations For BIND 9.9.9 through 9.9.9-P7, update to a version outside of this range to resolve the issue. For BIND 9.9.10b1 through 9.9.10rc2, update to a version outside of this range to resolve the issue. For BIND 9.10.4 through 9.10.4-P7, update to a version outside of this range to resolve the issue. For BIND 9.10.5b1 through 9.10.5rc2, update to a version outside of this range to resolve the issue. For BIND 9.11.0 through 9.11.0-P4, update to a version outside of this range to resolve the issue. For BIND 9.11.1b1 through 9.11.1rc2, update to a version outside of this range to resolve the issue. For BIND 9.9.9-S1 through 9.9.9-S9, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the control channel to minimize the risk of exploitation.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1464
CVE-2017-3138
DLA-957-1
DSA-3854-1
MGASA-2017-0478
OPENSUSE-SU-2017_1063-1
SUSE-SU-2017:0998-1
SUSE-SU-2017:0999-1
SUSE-SU-2017:1000-1
USN-3259-1

Affected Products

Alt Linux
Bind
Bind Server
Suse
Ubuntu