CVE-2017-3140 — Uncontrolled Resource Consumption in Bind
Severity
5.9MEDIUMNVD
CNA3.7
EPSS
19.5%
top 4.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16
Latest updateMay 13
Description
If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
3GHSA▶
GHSA-6f7c-h629-3xqv: If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop w↗2022-05-13
CVEList
▶
OSV▶
CVE-2017-3140: If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop w↗2019-01-16
📋Vendor Advisories
2💬Community
3Bugzilla▶
CVE-2017-3140 bind99: bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all]↗2017-06-15
Bugzilla▶
CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all]↗2017-06-15
Bugzilla▶
CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query↗2017-06-14