Severity
3.7LOW
EPSS
5.0%
top 10.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMay 14

Description

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages7 packages

Debianbind9< 1:9.10.3.dfsg.P4-12.4+3
Ubuntubind9< 1:9.9.5.dfsg-3ubuntu0.15+3
NVDisc/bind9.4.09.8.8+8
CVEListV5isc/bind_99.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.3, 7.4, 7.6, 7.5

🔴Vulnerability Details

5
GHSA
GHSA-jhf7-373h-xx92: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circ2022-05-14
CVEList
An error in TSIG authentication can permit unauthorized zone transfers2019-01-16
OSV
CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circ2019-01-16
OSV
bind9 regression2017-09-18
OSV
bind9 vulnerabilities2017-06-29

📋Vendor Advisories

5
Ubuntu
Bind vulnerabilities2017-11-08
Ubuntu
Bind regression2017-09-18
Red Hat
bind: An error in TSIG authentication can permit unauthorized zone transfers2017-06-29
Ubuntu
bind9 vulnerabilities2017-06-29
Debian
CVE-2017-3142: bind9 - An attacker who is able to send and receive messages to an authoritative DNS ser...2017

💬Community

3
Bugzilla
CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]2017-06-30
Bugzilla
CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all]2017-06-30
Bugzilla
CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers2017-06-29
CVE-2017-3142 (LOW CVSS 3.7) | An attacker who is able to send and | cvebase.io