CVE-2012-3817
published 2012-07-25CVE-2012-3817: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation…
PriorityP346high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
27.38%
97.8th percentile
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg.P1-4.2 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.2 (bookworm) |
| debian | isc-dhcp | < bind9 1:9.8.1.dfsg.P1-4.2 (bookworm) | bind9 1:9.8.1.dfsg.P1-4.2 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p54h-xvx8-c742: ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2012-3817 [HIGH] CWE-20 GHSA-p54h-xvx8-c742: ISC BIND 9
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
OSV
CVE-2012-3817: ISC BIND 9
osv·2012-07-25·CVSS 7.8
CVE-2012-3817 [HIGH] CVE-2012-3817: ISC BIND 9
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
VMware
VMware security updates for vSphere API and ESX Service Console
vendor_vmware·2012-11-15·CVSS 5.0
CVE-2011-4940 [MEDIUM] VMware security updates for vSphere API and ESX Service Console
VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
a. VMware vSphere API denial of service vulnerability The VMware vSphere API contains a denial of service vulnerability. This issue allows an unauthenticated user to send a maliciously crafted API request and disable the host daemon. Exploitation of the issue would prevent management activities on the host but any virtual machines running on the host would be unaffected. VMware would like to thank Sebastián Tello of Core Security Technologies for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5703 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is a
BSD
FreeBSD-SA-12:05.bind: named(8) DNSSEC validation Denial of Service
bsd_advisories·2012-08-06·CVSS 7.8
CVE-2012-3817 [HIGH] FreeBSD-SA-12:05.bind: named(8) DNSSEC validation Denial of Service
FreeBSD-SA-12:05.bind Security Advisory
The FreeBSD Project
Topic: named(8) DNSSEC validation Denial of Service
Category: contrib
Module: bind
Announced: 2012-08-06
Credits: Einar Lonn of IIS.se
Affects: All supported versions of FreeBSD
Corrected: 2012-08-06 21:33:11 UTC (RELENG_7, 7.4-STABLE)
2012-08-06 21:33:11 UTC (RELENG_7_4, 7.4-RELEASE-p10)
2012-07-24 19:04:35 UTC (RELENG_8, 8.3-STABLE)
2012-08-06 21:33:11 UTC (RELENG_8_3, 8.3-RELEASE-p4)
2012-08-06 21:33:11 UTC (RELENG_8_2, 8.2-RELEASE-p10)
2012-08-06 21:33:11 UTC (RELENG_8_1, 8.1-RELEASE-p13)
2012-07-24 22:32:03 UTC (RELENG_9, 9.1-PRERELEASE)
2012-08-06 21:33:11 UTC (RELENG_9_0, 9.0-RELEASE-p4)
CVE Name: CVE-2012-3817
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, secu
Ubuntu
Bind vulnerability
vendor_ubuntu·2012-07-26
CVE-2012-3817 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Einar Lonn discovered that Bind incorrectly initialized the failing-query
cache. A remote attacker could use this flaw to cause Bind to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: heavy DNSSEC validation load can cause assertion failure
vendor_redhat·2012-07-24·CVSS 7.8
CVE-2012-3817 [HIGH] bind: heavy DNSSEC validation load can cause assertion failure
bind: heavy DNSSEC validation load can cause assertion failure
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2012-3817: bind9 - ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; ...
vendor_debian·2012·CVSS 7.8
CVE-2012-3817 [HIGH] CVE-2012-3817: bind9 - ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; ...
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.2)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.2)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-4.2)
sid: resolved (fixed in 1:9.8.1.dfsg.P1-4.2)
trixie: resolved (fixed in 1:9.8.1.dfsg.P1-4.2)
No detection rules found.
No public exploits indexed.
arXiv
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
arxiv_fulltext·2023-10-04
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
https://faculty.sites.uci.edu/zhouli/research/ Qifan Zhang ,
https://faculty.sites.uci.edu/zhouli/research/ Xuesong Bai ,
https://netsec.ccert.edu.cn/people/lx19 Xiang Li ,
https://netsec.ccert.edu.cn/people/duanhx/ Haixin Duan ,
https://netsec.ccert.edu.cn/people/qli/ Qi Li , and
https://faculty.sites.uci.edu/zhouli/ Zhou Li
Corresponding authors. Most of Xiang Li's work was done when visiting UCI as a project specialist.
https://uci.edu/University of California, Irvine,
https://www.tsinghua.edu.cn/en/Tsinghua University
Zhongguancun Laboratory,
https://www.qcl.edu.cn/Quan Cheng Laboratory
## Abstract
Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache
Bugzilla
CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure
bugzilla·2012-07-24·CVSS 7.8
CVE-2012-3817 [HIGH] CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure
CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure
Upstream has released BIND versions 9.9.1-P2, 9.8.3-P2, 9.7.6-P2, and 9.6-ESV-R7-P2 to correct the following flaw:
BIND 9 stores a cache of query names that are known to be failing due to misconfigured name servers or a broken chain of trust. Under high query loads when DNSSEC validation is active, it is possible for a condition to arise in which data from this cache of failing queries could be used before it was fully initialized, triggering an assertion failure.
This bug cannot be encountered unless your server is doing DNSSEC validation.
9.4 and 9.5 are also reported to be affected by this flaw; it's likely that 9.3 is as well.
External Reference:
https://kb.isc.org/article/AA-00729
Discussion:
Created
Bugzilla
CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure [fedora-all]
bugzilla·2012-07-24·CVSS 7.8
CVE-2012-3817 [HIGH] CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure [fedora-all]
CVE-2012-3817 bind: heavy DNSSEC validation load can cause assertion failure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1122.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1123.htmlhttp://secunia.com/advisories/51096http://support.apple.com/kb/HT5880http://www.debian.org/security/2012/dsa-2517http://www.securitytracker.com/id?1027296http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004http://www.ubuntu.com/usn/USN-1518-1https://kb.isc.org/article/AA-00729http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1122.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1123.htmlhttp://secunia.com/advisories/51096http://support.apple.com/kb/HT5880http://www.debian.org/security/2012/dsa-2517http://www.securitytracker.com/id?1027296http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.536004http://www.ubuntu.com/usn/USN-1518-1https://kb.isc.org/article/AA-00729
2012-07-25
Published