cbcvebase.
CVE-2017-3142
published 2019-01-16

CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent…

PriorityP424low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
5.40%
91.8th percentile
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.10.3.dfsg.P4-12.4 (bookworm)bind9 1:9.10.3.dfsg.P4-12.4 (bookworm)
debiandebian_linux
debiandebian_linux
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind9.10.0 – 9.10.5
iscbind9.11.0 – 9.11.1
iscbind9.4.0 – 9.8.8
iscbind9.9.0 – 9.9.10
iscbind9>= 0 < 1:9.10.3.dfsg.P4-12.41:9.10.3.dfsg.P4-12.4
iscbind9>= 0 < 1:9.10.3.dfsg.P4-12.41:9.10.3.dfsg.P4-12.4
iscbind9>= 0 < 1:9.10.3.dfsg.P4-12.41:9.10.3.dfsg.P4-12.4
iscbind9>= 0 < 1:9.10.3.dfsg.P4-12.41:9.10.3.dfsg.P4-12.4
iscbind9>= 0 < 1:9.9.5.dfsg-3ubuntu0.151:9.9.5.dfsg-3ubuntu0.15
iscbind9>= 0 < 1:9.9.5.dfsg-3ubuntu0.161:9.9.5.dfsg-3ubuntu0.16
iscbind9>= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.71:9.10.3.dfsg.P4-8ubuntu1.7
iscbind9>= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.81:9.10.3.dfsg.P4-8ubuntu1.8
iscbind_9
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server

CVSS provenance

nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.