PT-2017-15684 · Isc+7 · Bind+7

Clã©Ment Berthaux

·

Published

2017-06-29

·

Updated

2024-06-15

·

CVE-2017-3142

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BIND versions 9.4.0 through 9.8.8 BIND versions 9.9.0 through 9.9.10-P1 BIND versions 9.10.0 through 9.10.5-P1 BIND versions 9.11.0 through 9.11.1-P1 BIND versions 9.9.3-S1 through 9.9.10-S2 BIND versions 9.10.5-S1 through 9.10.5-S2
Description The issue allows an attacker who can send and receive messages to an authoritative DNS server and has knowledge of a valid TSIG key name to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. This could result in providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. An attacker could exploit this by sending specially crafted data to bypass TSIG authentication and manipulate the server into accepting an unauthorized dynamic update.
Recommendations For BIND versions 9.4.0 through 9.8.8, update to a version outside of this range to mitigate the risk. For BIND versions 9.9.0 through 9.9.10-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.10.0 through 9.10.5-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.11.0 through 9.11.1-P1, update to a version outside of this range to mitigate the risk. For BIND versions 9.9.3-S1 through 9.9.10-S2, update to a version outside of this range to mitigate the risk. For BIND versions 9.10.5-S1 through 9.10.5-S2, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the TSIG key name and implementing additional ACL protection to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1966
CESA-2017_1679
CESA-2017_1680
CVE-2017-3142
DLA-1025-1
DSA-3904-1
DSA-3904-2
MGASA-2017-0478
OPENSUSE-SU-2017_1809-1
OPENSUSE-SU-2024:10650-1
RHSA-2017:1679
RHSA-2017:1680
RHSA-2017_1679
RHSA-2017_1680
SUSE-SU-2017:1736-1
SUSE-SU-2017:1737-1
SUSE-SU-2017:1738-1
SUSE-SU-2017_1736-1
SUSE-SU-2017_1737-1
SUSE-SU-2017_1738-1
USN-3346-1
USN-3346-2
USN-3346-3

Affected Products

Alt Linux
Bind
Bind Server
Centos
Ibm Aix
Red Hat
Suse
Ubuntu