Логотип exploitDog
bind:CVE-2017-3138
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-3138

Количество 9

Количество 9

ubuntu логотип

CVE-2017-3138

около 7 лет назад

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2017-3138

почти 9 лет назад

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2017-3138

около 7 лет назад

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2017-3138

около 7 лет назад

named contains a feature which allows operators to issue commands to a ...

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-q858-q2j2-9jg4

больше 3 лет назад

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 5.3
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2017:1063-1

почти 9 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1000-1

почти 9 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:0999-1

почти 9 лет назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:0998-1

почти 9 лет назад

Security update for bind

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-3138

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 6.5
39%
Средний
около 7 лет назад
redhat логотип
CVE-2017-3138

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 6.5
39%
Средний
почти 9 лет назад
nvd логотип
CVE-2017-3138

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 6.5
39%
Средний
около 7 лет назад
debian логотип
CVE-2017-3138

named contains a feature which allows operators to issue commands to a ...

CVSS3: 6.5
39%
Средний
около 7 лет назад
github логотип
GHSA-q858-q2j2-9jg4

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

CVSS3: 5.3
39%
Средний
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1063-1

Security update for bind

почти 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:1000-1

Security update for bind

почти 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0999-1

Security update for bind

почти 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:0998-1

Security update for bind

почти 9 лет назад

Уязвимостей на страницу