Логотип exploitDog
bind:CVE-2017-3142
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-3142

Количество 11

Количество 11

ubuntu логотип

CVE-2017-3142

почти 7 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-3142

больше 8 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-3142

почти 7 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-3142

почти 7 лет назад

An attacker who is able to send and receive messages to an authoritati ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jhf7-373h-xx92

больше 3 лет назад

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1809-1

больше 8 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1738-1

больше 8 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1737-1

больше 8 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1736-1

больше 8 лет назад

Security update for bind

EPSS: Низкий
oracle-oval логотип

ELSA-2017-1680

больше 8 лет назад

ELSA-2017-1680: bind security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-1679

больше 8 лет назад

ELSA-2017-1679: bind security and bug fix update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-3142

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.3
5%
Низкий
почти 7 лет назад
redhat логотип
CVE-2017-3142

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.3
5%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-3142

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 5.3
5%
Низкий
почти 7 лет назад
debian логотип
CVE-2017-3142

An attacker who is able to send and receive messages to an authoritati ...

CVSS3: 5.3
5%
Низкий
почти 7 лет назад
github логотип
GHSA-jhf7-373h-xx92

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVSS3: 3.7
5%
Низкий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1809-1

Security update for bind

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1738-1

Security update for bind

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1737-1

Security update for bind

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1736-1

Security update for bind

больше 8 лет назад
oracle-oval логотип
ELSA-2017-1680

ELSA-2017-1680: bind security and bug fix update (IMPORTANT)

больше 8 лет назад
oracle-oval логотип
ELSA-2017-1679

ELSA-2017-1679: bind security and bug fix update (IMPORTANT)

больше 8 лет назад

Уязвимостей на страницу