Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

fstec логотип

BDU:2018-00105

около 9 лет назад

Уязвимость реализации протокола TSIG DNS-сервера BIND, позволяющая нарушителю обойти процедуру аутентификации и получить корректную подпись для произвольных данных

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2017-3143

больше 7 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2017-3143

около 9 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2017-3143

больше 7 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2017-3143

больше 7 лет назад

An attacker who is able to send and receive messages to an authoritati ...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-jxfm-jqx8-8h25

около 4 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2017:1809-1

около 9 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1738-1

около 9 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1737-1

около 9 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1736-1

около 9 лет назад

Security update for bind

EPSS: Низкий
oracle-oval логотип

ELSA-2017-1680

около 9 лет назад

ELSA-2017-1680: bind security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-1679

около 9 лет назад

ELSA-2017-1679: bind security and bug fix update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2018-00105

Уязвимость реализации протокола TSIG DNS-сервера BIND, позволяющая нарушителю обойти процедуру аутентификации и получить корректную подпись для произвольных данных

CVSS3: 7.5
18%
Средний
около 9 лет назад
ubuntu логотип
CVE-2017-3143

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 7.5
18%
Средний
больше 7 лет назад
redhat логотип
CVE-2017-3143

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 7.5
18%
Средний
около 9 лет назад
nvd логотип
CVE-2017-3143

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 7.5
18%
Средний
больше 7 лет назад
debian логотип
CVE-2017-3143

An attacker who is able to send and receive messages to an authoritati ...

CVSS3: 7.5
18%
Средний
больше 7 лет назад
github логотип
GHSA-jxfm-jqx8-8h25

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.9
18%
Средний
около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1809-1

Security update for bind

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:1738-1

Security update for bind

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:1737-1

Security update for bind

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:1736-1

Security update for bind

около 9 лет назад
oracle-oval логотип
ELSA-2017-1680

ELSA-2017-1680: bind security and bug fix update (IMPORTANT)

около 9 лет назад
oracle-oval логотип
ELSA-2017-1679

ELSA-2017-1679: bind security and bug fix update (IMPORTANT)

около 9 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.