CVE-2017-3137
published 2019-10-30CVE-2017-3137: The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
8.90%
94.7th percentile
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.9.3.dfsg.P2-1 (bookworm) | bind9 1:9.9.3.dfsg.P2-1 (bookworm) |
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-12.3 (bookworm) | bind9 1:9.10.3.dfsg.P4-12.3 (bookworm) |
| debian | bind9 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.9.3.dfsg.P2-1 | 1:9.9.3.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.3 | 1:9.10.3.dfsg.P4-12.3 |
| isc | bind9 | >= 0 < 1:9.9.3.dfsg.P2-1 | 1:9.9.3.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.3 | 1:9.10.3.dfsg.P4-12.3 |
| isc | bind9 | >= 0 < 1:9.9.3.dfsg.P2-1 | 1:9.9.3.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.3 | 1:9.10.3.dfsg.P4-12.3 |
| isc | bind9 | >= 0 < 1:9.9.3.dfsg.P2-1 | 1:9.9.3.dfsg.P2-1 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.3 | 1:9.10.3.dfsg.P4-12.3 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.14 | 1:9.9.5.dfsg-3ubuntu0.14 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.6 | 1:9.10.3.dfsg.P4-8ubuntu1.6 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qp2w-qqh3-4x36: The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2018-5735 [HIGH] CWE-617 GHSA-qp2w-qqh3-4x36: The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
GHSA
GHSA-wmp5-3j44-5x2x: Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situ
ghsa_unreviewed·2022-05-13
CVE-2017-3137 [HIGH] CWE-617 GHSA-wmp5-3j44-5x2x: Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situ
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
OSV
CVE-2018-5735: The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator
osv·2019-10-30·CVSS 7.5
CVE-2018-5735 [HIGH] CVE-2018-5735: The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
OSV
CVE-2017-3137: Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situ
osv·2019-01-16·CVSS 7.5
CVE-2017-3137 [HIGH] CVE-2017-3137: Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situ
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
OSV
bind9 vulnerabilities
osv·2017-04-17·CVSS 5.9
CVE-2017-3137 [MEDIUM] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that the resolver in Bind made incorrect
assumptions about ordering when processing responses containing
a CNAME or DNAME. An attacker could use this cause a denial of
service. (CVE-2017-3137)
Oleg Gorokhov discovered that in some situations, Bind did not properly
handle DNS64 queries. An attacker could use this to cause a denial
of service. (CVE-2017-3136)
Mike Lalumiere discovered that in some situations, Bind did
not properly handle invalid operations requested via its control
channel. An attacker with access to the control channel could cause
a denial of service. (CVE-2017-3138)
Red Hat
bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
vendor_redhat·2018-02-19·CVSS 7.5
CVE-2018-5735 [HIGH] CWE-617 bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
Statement: This issue is the same as CVE-2017-3139. For more information, refer to CVE-2017-3139.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red
Debian
CVE-2018-5735: bind9 - The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in v...
vendor_debian·2018·CVSS 7.5
CVE-2018-5735 [HIGH] CVE-2018-5735: bind9 - The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in v...
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
Scope: local
bookworm: resolved (fixed in 1:9.9.3.dfsg.P2-1)
bullseye: resolved (fixed in 1:9.9.3.dfsg.P2-1)
forky: resolved (fixed in 1:9.9.3.dfsg.P2-1)
sid: resolved (fixed in 1:9.9.3.dfsg.P2-1)
trixie: resolved (fixed in 1:9.9.3.dfsg.P2-1)
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-04-17·CVSS 5.9
CVE-2017-3136 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
It was discovered that the resolver in Bind made incorrect
assumptions about ordering when processing responses containing
a CNAME or DNAME. An attacker could use this cause a denial of
service. (CVE-2017-3137)
Oleg Gorokhov discovered that in some situations, Bind did not properly
handle DNS64 queries. An attacker could use this to cause a denial
of service. (CVE-2017-3136)
Mike Lalumiere discovered that in some situations, Bind did
not properly handle invalid operations requested via its control
channel. An attacker with access to the control channel could cause
a denial of service. (CVE-2017-3138)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
vendor_redhat·2017-04-12·CVSS 7.5
CVE-2017-3137 [HIGH] CWE-617 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
A denial of service flaw was found in the way BIND handled a query response containing CNAME or DNAME resource records in an unusual order. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Package: bind (Red Hat Ente
Debian
CVE-2017-3137: bind9 - Mistaken assumptions about the ordering of records in the answer section of a re...
vendor_debian·2017·CVSS 7.5
CVE-2017-3137 [HIGH] CVE-2017-3137: bind9 - Mistaken assumptions about the ordering of records in the answer section of a re...
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-12.3)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-12.3)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-12.3)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-12.3)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-12.3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3137 bind99: bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver [fedora-all]
bugzilla·2017-04-13·CVSS 7.5
CVE-2017-3137 [HIGH] CVE-2017-3137 bind99: bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver [fedora-all]
CVE-2017-3137 bind99: bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver [fedora-all]
bugzilla·2017-04-13·CVSS 7.5
CVE-2017-3137 [HIGH] CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver [fedora-all]
CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
bugzilla·2017-04-11·CVSS 7.5
CVE-2017-3137 [HIGH] CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
CVE-2017-3137 bind: Processing a response containing CNAME or DNAME with unusual order can crash resolver
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order.
A server which is performing recursion can be forced to exit with an assertion failure if it can be caused to receive a response containing CNAME or DNAME resource records with certain ordering. An attacker can cause a denial of service by exploiting this condition. Recursive resolvers are at highest risk but authoritative servers are theoretically vulnerable if they perform recursion.
External References:
2019-10-30
Published