CVE-2017-3139
published 2019-04-09CVE-2017-3139: A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.63%
73.4th percentile
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| red_hat | bind | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
vendor_redhat·2018-02-19·CVSS 7.5
CVE-2018-5735 [HIGH] CWE-617 bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
Statement: This issue is the same as CVE-2017-3139. For more information, refer to CVE-2017-3139.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red
Red Hat
bind: assertion failure in DNSSEC validation
vendor_redhat·2017-05-08·CVSS 7.5
CVE-2017-3139 [HIGH] bind: assertion failure in DNSSEC validation
bind: assertion failure in DNSSEC validation
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Statement: This issue affected only the BIND versions as shipped with Red Hat Enterprise Linux 6. This issue did not affect any upstream versions of BIND. This issue does not affect BIND configurations which have DNSSEC validation turned off.
Package: bind (Red Hat Enterprise Linux 5) - Will not fix
Package: bind97 (Red Hat
Debian
CVE-2017-3139: bind9 - A denial of service flaw was found in the way BIND handled DNSSEC validation. A ...
vendor_debian·2017·CVSS 7.5
CVE-2017-3139 [HIGH] CVE-2017-3139: bind9 - A denial of service flaw was found in the way BIND handled DNSSEC validation. A ...
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-qr8v-h24f-rg77: A denial of service flaw was found in the way BIND handled DNSSEC validation
ghsa_unreviewed·2022-05-13
CVE-2017-3139 [HIGH] CWE-617 GHSA-qr8v-h24f-rg77: A denial of service flaw was found in the way BIND handled DNSSEC validation
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5735 bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
bugzilla·2018-03-05·CVSS 7.5
CVE-2018-5735 [HIGH] CVE-2018-5735 bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
CVE-2018-5735 bind: Assertion failure in validator.c due to incorrect handling of DNSSEC validation
It was discovered that Bind incorrectly handled DNSSEC validation. An attacker could possibly use this to cause a denial of service.
Upstream patch:
https://source.isc.org/cgi-bin/gitweb.cgi/?p=bind9.git;a=commit;h=07dbb507d2913fc35c7edbe3692a976e3248a911
NOTE: This issue is the same as CVE-2017-3139 which was specifically assigned for Red Hat product.
Discussion:
Statement:
This issue is the same as CVE-2017-3139. For more information, refer to CVE-2017-3139.
Bugzilla
CVE-2017-3139 bind: assertion failure in DNSSEC validation
bugzilla·2017-05-03·CVSS 7.5
CVE-2017-3139 [HIGH] CVE-2017-3139 bind: assertion failure in DNSSEC validation
CVE-2017-3139 bind: assertion failure in DNSSEC validation
A denial of service flaw was found in the way BIND versions as shipped with RHEL 6 handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
This issue does not affect the upstream versions of BIND.
This issue does not affect BIND configurations which have DNSSEC validation turned off.
Discussion:
Statement:
This issue affected only the BIND versions as shipped with Red Hat Enterprise Linux 6. This issue did not affect any upstream versions of BIND. This issue does not affect BIND configurations which have DNSSEC validation turned off.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
2019-04-09
Published