Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-3137

Опубликовано: 12 апр. 2017
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.

A denial of service flaw was found in the way BIND handled a query response containing CNAME or DNAME resource records in an unusual order. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bindWill not fix
Red Hat Enterprise Linux 5bind97Will not fix
Red Hat Enterprise Linux 6bindFixedRHSA-2017:110520.04.2017
Red Hat Enterprise Linux 6.2 Advanced Update SupportbindFixedRHSA-2017:158228.06.2017
Red Hat Enterprise Linux 6.4 Advanced Update SupportbindFixedRHSA-2017:158228.06.2017
Red Hat Enterprise Linux 6.5 Advanced Update SupportbindFixedRHSA-2017:158228.06.2017
Red Hat Enterprise Linux 6.5 Telco Extended Update SupportbindFixedRHSA-2017:158228.06.2017
Red Hat Enterprise Linux 6.6 Advanced Update SupportbindFixedRHSA-2017:158228.06.2017
Red Hat Enterprise Linux 6.6 Telco Extended Update SupportbindFixedRHSA-2017:158228.06.2017
Red Hat Enterprise Linux 6.7 Extended Update SupportbindFixedRHSA-2017:158228.06.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1441133bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver

EPSS

Процентиль: 97%
0.34588
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.

CVSS3: 7.5
nvd
почти 7 лет назад

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.

CVSS3: 7.5
debian
почти 7 лет назад

Mistaken assumptions about the ordering of records in the answer secti ...

suse-cvrf
больше 8 лет назад

Security update for bind

CVSS3: 7.5
github
больше 3 лет назад

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.

EPSS

Процентиль: 97%
0.34588
Средний

7.5 High

CVSS3