CVE-2017-3142
published 2019-01-16CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent…
PriorityP424low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
5.40%
91.8th percentile
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-12.4 (bookworm) | bind9 1:9.10.3.dfsg.P4-12.4 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.10.0 – 9.10.5 | — |
| isc | bind | 9.11.0 – 9.11.1 | — |
| isc | bind | 9.4.0 – 9.8.8 | — |
| isc | bind | 9.9.0 – 9.9.10 | — |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.15 | 1:9.9.5.dfsg-3ubuntu0.15 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.16 | 1:9.9.5.dfsg-3ubuntu0.16 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.7 | 1:9.10.3.dfsg.P4-8ubuntu1.7 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.8 | 1:9.10.3.dfsg.P4-8ubuntu1.8 |
| isc | bind_9 | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-11-08·CVSS 5.3
CVE-2017-3142 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to serve incorrect information or expose sensitive
information over the network.
USN-3346-1 and USN-3346-2 fixed two vulnerabilities in Bind and a regression,
respectively. This update provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
In addition, this update adds the new root zone key signing key (KSK).
Instructions: After a
Ubuntu
Bind regression
vendor_ubuntu·2017-09-18·CVSS 5.3
CVE-2017-3142 [MEDIUM] Bind regression
Title: Bind regression
Summary: USN-3346-1 introduced a regression in Bind.
USN-3346-1 fixed vulnerabilities in Bind. The fix for CVE-2017-3142
introduced a regression in the ability to receive an AXFR or IXFR in the
case where TSIG is used and not every message is signed. This update fixes
the problem.
In addition, this update adds the new root zone key signing key (KSK).
Original advisory details:
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
Instructions:
Red Hat
bind: An error in TSIG authentication can permit unauthorized zone transfers
vendor_redhat·2017-06-29·CVSS 5.3
CVE-2017-3142 [MEDIUM] CWE-287 bind: An error in TSIG authentication can permit unauthorized zone transfers
bind: An error in TSIG authentication can permit unauthorized zone transfers
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
A flaw was found in the way BIND handled TSIG authentication of AXFR requests. A remote attacker, able to communicate with an authoritative BIND server,
Ubuntu
bind9 vulnerabilities
vendor_ubuntu·2017-06-29·CVSS 5.3
CVE-2017-3142 [MEDIUM] bind9 vulnerabilities
Title: bind9 vulnerabilities
Summary: Bind could be made to serve incorrect information or expose sensitive
information over the network.
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
Instructions: After a standard system update you need to restart Bind to make
all the necessary changes.
Debian
CVE-2017-3142: bind9 - An attacker who is able to send and receive messages to an authoritative DNS ser...
vendor_debian·2017·CVSS 5.3
CVE-2017-3142 [MEDIUM] CVE-2017-3142: bind9 - An attacker who is able to send and receive messages to an authoritative DNS ser...
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
trixie: resolved (f
GHSA
GHSA-jhf7-373h-xx92: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circ
ghsa_unreviewed·2022-05-14
CVE-2017-3142 [MEDIUM] CWE-20 GHSA-jhf7-373h-xx92: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circ
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
OSV
CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circ
osv·2019-01-16·CVSS 3.7
CVE-2017-3142 [LOW] CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circ
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
OSV
bind9 regression
osv·2017-09-18·CVSS 3.7
CVE-2017-3142 [LOW] bind9 regression
bind9 regression
USN-3346-1 fixed vulnerabilities in Bind. The fix for CVE-2017-3142
introduced a regression in the ability to receive an AXFR or IXFR in the
case where TSIG is used and not every message is signed. This update fixes
the problem.
In addition, this update adds the new root zone key signing key (KSK).
Original advisory details:
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
OSV
bind9 vulnerabilities
osv·2017-06-29·CVSS 3.7
CVE-2017-3143 [LOW] bind9 vulnerabilities
bind9 vulnerabilities
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
No detection rules found.
No public exploits indexed.
RFC
Secret Key Transaction Authentication for DNS (TSIG)
rfc·2020-11-01
Secret Key Transaction Authentication for DNS (TSIG)
Internet Engineering Task Force (IETF) F. Dupont
Request for Comments: 8945 ISC
STD: 93 S. Morris
Obsoletes: 2845, 4635 Unaffiliated
Category: Standards Track P. Vixie
ISSN: 2070-1721 Farsight
D. Eastlake 3rd
Futurewei
O. Gudmundsson
Cloudflare
B. Wellington
Akamai
November 2020
Secret Key Transaction Authentication for DNS (TSIG)
Abstract
This document describes a protocol for transaction-level
authentication using shared secrets and one-way hashing. It can be
used to authenticate dynamic updates to a DNS zone as coming from an
approved client or to authenticate responses as coming from an
approved name server.
No recommendation is made here for distributing the shared secrets;
it is expected that a network administrator will statically configure
name servers and clients using so
Bugzilla
CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]
bugzilla·2017-06-30·CVSS 5.3
CVE-2017-3142 [MEDIUM] CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]
CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]
bugzilla·2017-06-30·CVSS 5.3
CVE-2017-3142 [MEDIUM] CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]
CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers
bugzilla·2017-06-29·CVSS 5.3
CVE-2017-3142 [MEDIUM] CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers
CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers
An attacker able to send and receive messages to an authoritative DNS server may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into:
* providing an AXFR of a zone to an unauthorized recipient
* accepting bogus Notify packets
An unauthorized AXFR (full zone transfer) permits an attacker to view the entire contents of a zone. Protection of zone contents is often a commercial or business requirement.
If accepted, a Notify sets the zone refresh interval to 'now'. If there is not already a refresh cycle in progress then named will initiate o
http://www.securityfocus.com/bid/99339http://www.securitytracker.com/id/1038809https://access.redhat.com/errata/RHSA-2017:1679https://access.redhat.com/errata/RHSA-2017:1680https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03772en_ushttps://kb.isc.org/docs/aa-01504https://security.netapp.com/advisory/ntap-20190830-0003/https://www.debian.org/security/2017/dsa-3904http://www.securityfocus.com/bid/99339http://www.securitytracker.com/id/1038809https://access.redhat.com/errata/RHSA-2017:1679https://access.redhat.com/errata/RHSA-2017:1680https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03772en_ushttps://kb.isc.org/docs/aa-01504https://security.netapp.com/advisory/ntap-20190830-0003/https://www.debian.org/security/2017/dsa-3904
2019-01-16
Published