PT-2017-3340 · Isc+7 · Bind+7

Clã©Ment Berthaux

·

Published

2017-06-29

·

Updated

2019-10-03

·

CVE-2017-3143

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BIND versions 9.4.0 through 9.8.8 BIND versions 9.9.0 through 9.9.10-P1 BIND versions 9.10.0 through 9.10.5-P1 BIND versions 9.11.0 through 9.11.1-P1 BIND versions 9.9.3-S1 through 9.9.10-S2 BIND versions 9.10.5-S1 through 9.10.5-S2
Description The issue is related to errors in the implementation of the TSIG authentication procedure in the BIND DNS server. An attacker who can send and receive messages to an authoritative DNS server and has knowledge of a valid TSIG key name for the targeted zone and service may be able to manipulate BIND into accepting an unauthorized dynamic update. This could allow the attacker to bypass TSIG authentication and obtain a legitimate signature for arbitrary messages using a specially crafted TSIG sequence.
Recommendations For BIND versions 9.4.0 through 9.8.8, update to a version outside of this range to resolve the issue. For BIND versions 9.9.0 through 9.9.10-P1, update to a version outside of this range to resolve the issue. For BIND versions 9.10.0 through 9.10.5-P1, update to a version outside of this range to resolve the issue. For BIND versions 9.11.0 through 9.11.1-P1, update to a version outside of this range to resolve the issue. For BIND versions 9.9.3-S1 through 9.9.10-S2, update to a version outside of this range to resolve the issue. For BIND versions 9.10.5-S1 through 9.10.5-S2, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the TSIG authentication mechanism until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1966
BDU:2018-00105
CESA-2017_1679
CESA-2017_1680
CVE-2017-3143
DLA-1025-1
DSA-3904-1
MGASA-2017-0478
OPENSUSE-SU-2017_1809-1
RHSA-2017:1679
RHSA-2017:1680
RHSA-2017_1679
RHSA-2017_1680
SUSE-SU-2017:1736-1
SUSE-SU-2017:1737-1
SUSE-SU-2017:1738-1
USN-3346-1
USN-3346-2
USN-3346-3

Affected Products

Alt Linux
Bind
Bind Server
Centos
Ibm Aix
Red Hat
Suse
Ubuntu