Описание
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
A denial of service flaw was found in the way BIND handled a query response containing CNAME or DNAME resource records in an unusual order. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind | Will not fix | ||
| Red Hat Enterprise Linux 5 | bind97 | Will not fix | ||
| Red Hat Enterprise Linux 6 | bind | Fixed | RHSA-2017:1105 | 20.04.2017 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | bind | Fixed | RHSA-2017:1582 | 28.06.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
Mistaken assumptions about the ordering of records in the answer secti ...
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
EPSS
7.5 High
CVSS3