Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-3140

Опубликовано: 14 июн. 2017
Источник: redhat
CVSS3: 3.7
EPSS Средний

Описание

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

A denial of service flaw was found in the way BIND handled processing of NSDNAME and NSIP rules. A remote attacker could use this flaw to make named enter an infinite loop by sending a specially crafted query, thus resulting in denial-of-service.

Отчет

This issue did not affect the versions of BIND as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bindNot affected
Red Hat Enterprise Linux 5bind97Not affected
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1461302bind: Error processing RPZ rules leads to endless loop while handling query

EPSS

Процентиль: 95%
0.19519
Средний

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 7 лет назад

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

CVSS3: 3.7
nvd
около 7 лет назад

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

CVSS3: 3.7
debian
около 7 лет назад

If named is configured to use Response Policy Zones (RPZ) an error pro ...

CVSS3: 5.9
github
больше 3 лет назад

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

EPSS

Процентиль: 95%
0.19519
Средний

3.7 Low

CVSS3