CVE-2016-9147
published 2017-01-12CVE-2016-9147: named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
24.60%
97.7th percentile
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-11 (bookworm) | bind9 1:9.10.3.dfsg.P4-11 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-11 | 1:9.10.3.dfsg.P4-11 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.11 | 1:9.9.5.dfsg-3ubuntu0.11 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.4 | 1:9.10.3.dfsg.P4-8ubuntu1.4 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9131)
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9147)
It was discovered that Bind incorrectly handled certain malformed DS record
responses. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444
Red Hat
bind: assertion failure while handling a query response containing inconsistent DNSSEC information
vendor_redhat·2017-01-11·CVSS 7.5
CVE-2016-9147 [HIGH] bind: assertion failure while handling a query response containing inconsistent DNSSEC information
bind: assertion failure while handling a query response containing inconsistent DNSSEC information
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
A denial of service flaw was found in the way BIND handled a query response containing inconsistent DNSSEC information. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Debian
CVE-2016-9147: bind9 - named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote att...
vendor_debian·2016·CVSS 7.5
CVE-2016-9147 [HIGH] CVE-2016-9147: bind9 - named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote att...
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-11)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-11)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-11)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-11)
GHSA
GHSA-q76v-gxg3-wx5g: named in ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2016-9147 [HIGH] CWE-20 GHSA-q76v-gxg3-wx5g: named in ISC BIND 9
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
OSV
CVE-2016-9147: named in ISC BIND 9
osv·2017-01-12·CVSS 7.5
CVE-2016-9147 [HIGH] CVE-2016-9147: named in ISC BIND 9
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
OSV
bind9 vulnerabilities
osv·2017-01-12·CVSS 7.5
CVE-2016-9131 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9131)
It was discovered that Bind incorrectly handled certain malformed responses
to an ANY query. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2016-9147)
It was discovered that Bind incorrectly handled certain malformed DS record
responses. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9147 bind99: bind: assertion failure while handling a query response containing inconsistent DNSSEC information [fedora-all]
bugzilla·2017-01-12·CVSS 7.5
CVE-2016-9147 [HIGH] CVE-2016-9147 bind99: bind: assertion failure while handling a query response containing inconsistent DNSSEC information [fedora-all]
CVE-2016-9147 bind99: bind: assertion failure while handling a query response containing inconsistent DNSSEC information [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information [fedora-all]
bugzilla·2017-01-12·CVSS 7.5
CVE-2016-9147 [HIGH] CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information [fedora-all]
CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information
bugzilla·2017-01-09·CVSS 7.5
CVE-2016-9147 [HIGH] CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information
CVE-2016-9147 bind: assertion failure while handling a query response containing inconsistent DNSSEC information
An error handling a query response containing inconsistent DNSSEC information could cause an assertion failure.
Depending on the type of query and the EDNS options in the query they receive, DNSSEC-enabled authoritative servers are expected to include RRSIG and other RRsets in their responses to recursive servers. DNSSEC validating servers will also make specific queries for DS and other RRsets. Whether DNSSEC-validating or not, an error in processing malformed query responses that contain DNSSEC-related RRsets that are inconsistent with other RRsets in the same query response can trigger an assertion failure. Although the combination of properties which triggers the assertion
Fortinet
The Analysis of ISC BIND NSEC Record Handling DoS (CVE-2016-9147)
blogs_fortinet·2017-01-25·CVSS 7.5
CVE-2016-9147 [HIGH] The Analysis of ISC BIND NSEC Record Handling DoS (CVE-2016-9147)
FORTIGUARD LABS THREAT RESEARCH
The Analysis of ISC BIND NSEC Record Handling DoS (CVE-2016-9147)
By Dehui Yin | January 25, 2017
The latest patch for BIND from the Internet Systems Consortium (ISC) fixes a NESC record-related bug. Remote BIND recursive servers may crash when attempting to handle the specifically-crafted query response with NESC record sent by attackers, thereby causing a denial of service (DoS).
This potential DoS vulnerability is caused by a RUNTIME CHECK error in Resolver.c when caching the DNS response with NSEC Record. In this post we will examine the BIND source codes and expose the root cause of this vulnerability.
The NSEC record (record type 47) is provided by the Domain Name System Security Extensions (DNSSEC) to handle non-existent names in DNS. It links all
http://rhn.redhat.com/errata/RHSA-2017-0062.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0063.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0064.htmlhttp://www.debian.org/security/2017/dsa-3758http://www.securityfocus.com/bid/95390http://www.securitytracker.com/id/1037582https://access.redhat.com/errata/RHSA-2017:1582https://access.redhat.com/errata/RHSA-2017:1583https://kb.isc.org/article/AA-01440/74/CVE-2016-9147https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/http://rhn.redhat.com/errata/RHSA-2017-0062.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0063.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0064.htmlhttp://www.debian.org/security/2017/dsa-3758http://www.securityfocus.com/bid/95390http://www.securitytracker.com/id/1037582https://access.redhat.com/errata/RHSA-2017:1582https://access.redhat.com/errata/RHSA-2017:1583https://kb.isc.org/article/AA-01440/74/CVE-2016-9147https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/
2017-01-12
Published