CVE Database
/

CVE-2017-3137

Back to search

CVE-2017-3137

Published: Jan 16, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.

VendorProductVersions

ISC

BIND 9

affected
9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

RHSA-2017:1095
vendor-advisory
x_refsource_REDHAT
GLSA-201708-01
vendor-advisory
x_refsource_GENTOO
1038258
vdb-entry
x_refsource_SECTRACK
1040195
vdb-entry
x_refsource_SECTRACK
RHSA-2017:1582
vendor-advisory
x_refsource_REDHAT
DSA-3854
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:1583
vendor-advisory
x_refsource_REDHAT
97651
vdb-entry
x_refsource_BID
RHSA-2017:1105
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now