CVE-2017-3138Reachable Assertion in Bind 9

CWE-617Reachable Assertion12 documents8 sources
Severity
5.3MEDIUMNVD
CNA6.5
EPSS
37.9%
top 2.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMay 13

Description

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages3 packages

Debianisc/bind9< 1:9.10.3.dfsg.P4-12.3+3
NVDisc/bind6 versions+5
CVEListV5isc/bind_99.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9

Also affects: Debian Linux 8.0

🔴Vulnerability Details

4
GHSA
GHSA-q858-q2j2-9jg4: named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel,2022-05-13
CVEList
named exits with a REQUIRE assertion failure if it receives a null command string on its control channel2019-01-16
OSV
CVE-2017-3138: named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel,2019-01-16
OSV
bind9 vulnerabilities2017-04-17

📋Vendor Advisories

3
Ubuntu
Bind vulnerabilities2017-04-17
Red Hat
bind: REQUIRE assertion failure when null command string on control channel is received2017-04-12
Debian
CVE-2017-3138: bind9 - named contains a feature which allows operators to issue commands to a running s...2017

💬Community

4
Bugzilla
CVE-2017-15113 ovirt-engine: DEBUG logging includes unmasked passwords2017-11-13
Bugzilla
CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received [fedora-all]2017-04-13
Bugzilla
CVE-2017-3138 bind99: bind: REQUIRE assertion failure when null command string on control channel is received [fedora-all]2017-04-13
Bugzilla
CVE-2017-3138 bind: REQUIRE assertion failure when null command string on control channel is received2017-04-11
CVE-2017-3138 — Reachable Assertion in ISC Bind 9 | cvebase