CVE-2017-3135
published 2019-01-16CVE-2017-3135: Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an…
PriorityP340medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
17.24%
96.8th percentile
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-12 (bookworm) | bind9 1:9.10.3.dfsg.P4-12 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12 | 1:9.10.3.dfsg.P4-12 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12 | 1:9.10.3.dfsg.P4-12 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12 | 1:9.10.3.dfsg.P4-12 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12 | 1:9.10.3.dfsg.P4-12 |
| isc | bind_9 | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-02-16
CVE-2017-3135 Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled rewriting certain query
responses when using both DNS64 and RPZ. A remote attacker could possibly
use this issue to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash
vendor_redhat·2017-02-08·CVSS 7.5
CVE-2017-3135 [HIGH] bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash
bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
A denial of service flaw was found in the way BIND handled query responses when both DNS64 and RPZ were used. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure or a null pointer dereference via a specially crafted DNS response.
Mitigation: While it is possible to avoid the condition by removing either DNS64 or RPZ from the c
Debian
CVE-2017-3135: bind9 - Under some conditions when using both DNS64 and RPZ to rewrite query responses, ...
vendor_debian·2017·CVSS 7.5
CVE-2017-3135 [HIGH] CVE-2017-3135: bind9 - Under some conditions when using both DNS64 and RPZ to rewrite query responses, ...
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-12)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-12)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-12)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-12)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-12)
GHSA
GHSA-369c-w4jq-mxgx: Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either
ghsa_unreviewed·2022-05-13
CVE-2017-3135 [MEDIUM] CWE-476 GHSA-369c-w4jq-mxgx: Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
OSV
CVE-2017-3135: Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either
osv·2019-01-16·CVSS 5.9
CVE-2017-3135 [MEDIUM] CVE-2017-3135: Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3135 bind99: bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash [fedora-all]
bugzilla·2017-02-09·CVSS 7.5
CVE-2017-3135 [HIGH] CVE-2017-3135 bind99: bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash [fedora-all]
CVE-2017-3135 bind99: bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash [fedora-all]
bugzilla·2017-02-09·CVSS 7.5
CVE-2017-3135 [HIGH] CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash [fedora-all]
CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash
bugzilla·2017-02-08·CVSS 7.5
CVE-2017-3135 [HIGH] CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash
CVE-2017-3135 bind: Assertion failure when using DNS64 and RPZ Can Lead to Crash
As per upstream advisory:
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer.
Impact:
Servers utilizing both DNS64 and RPZ are potentially susceptible to encountering this condition. When this condition occurs, it will result in either an INSIST assertion failure (and subsequent abort) or an attempt to read through a NULL pointer. On most platforms a NULL pointer read leads to a segmentation fault (SEGFAULT), which causes the process to be terminated.
Only servers which are configured to simultaneously use both Response Policy Zones (R
http://rhn.redhat.com/errata/RHSA-2017-0276.htmlhttp://www.securityfocus.com/bid/96150http://www.securitytracker.com/id/1037801https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03747en_ushttps://kb.isc.org/docs/aa-01453https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/https://www.debian.org/security/2017/dsa-3795http://rhn.redhat.com/errata/RHSA-2017-0276.htmlhttp://www.securityfocus.com/bid/96150http://www.securitytracker.com/id/1037801https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03747en_ushttps://kb.isc.org/docs/aa-01453https://security.gentoo.org/glsa/201708-01https://security.netapp.com/advisory/ntap-20180926-0005/https://www.debian.org/security/2017/dsa-3795
2019-01-16
Published