CVE-2017-3140Uncontrolled Resource Consumption in Bind

Severity
5.9MEDIUMNVD
CNA3.7
EPSS
19.5%
top 4.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16
Latest updateMay 13

Description

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

Alpineisc/bind< 9.11.3-r0+1
NVDisc/bind9.11.09.11.1+2
CVEListV5isc/bind_99.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1

🔴Vulnerability Details

3
GHSA
GHSA-6f7c-h629-3xqv: If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop w2022-05-13
CVEList
An error processing RPZ rules can cause named to loop endlessly after handling a query2019-01-16
OSV
CVE-2017-3140: If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop w2019-01-16

📋Vendor Advisories

2
Red Hat
bind: Error processing RPZ rules leads to endless loop while handling query2017-06-14
Debian
CVE-2017-3140: bind9 - If named is configured to use Response Policy Zones (RPZ) an error processing so...2017

💬Community

3
Bugzilla
CVE-2017-3140 bind99: bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all]2017-06-15
Bugzilla
CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all]2017-06-15
Bugzilla
CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query2017-06-14
CVE-2017-3140 — Uncontrolled Resource Consumption | cvebase