CVE-2017-3143
published 2019-01-16CVE-2017-3143: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service…
PriorityP346medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
18.16%
96.9th percentile
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.10.3.dfsg.P4-12.4 (bookworm) | bind9 1:9.10.3.dfsg.P4-12.4 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.10.0 – 9.10.5 | — |
| isc | bind | 9.11.0 – 9.11.1 | — |
| isc | bind | 9.4.0 – 9.8.8 | — |
| isc | bind | 9.9.0 – 9.9.10 | — |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-12.4 | 1:9.10.3.dfsg.P4-12.4 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.15 | 1:9.9.5.dfsg-3ubuntu0.15 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.16 | 1:9.9.5.dfsg-3ubuntu0.16 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.7 | 1:9.10.3.dfsg.P4-8ubuntu1.7 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.8 | 1:9.10.3.dfsg.P4-8ubuntu1.8 |
| isc | bind_9 | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2017-11-08·CVSS 5.3
CVE-2017-3142 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to serve incorrect information or expose sensitive
information over the network.
USN-3346-1 and USN-3346-2 fixed two vulnerabilities in Bind and a regression,
respectively. This update provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
In addition, this update adds the new root zone key signing key (KSK).
Instructions: After a
Ubuntu
Bind regression
vendor_ubuntu·2017-09-18·CVSS 5.3
CVE-2017-3142 [MEDIUM] Bind regression
Title: Bind regression
Summary: USN-3346-1 introduced a regression in Bind.
USN-3346-1 fixed vulnerabilities in Bind. The fix for CVE-2017-3142
introduced a regression in the ability to receive an AXFR or IXFR in the
case where TSIG is used and not every message is signed. This update fixes
the problem.
In addition, this update adds the new root zone key signing key (KSK).
Original advisory details:
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
Instructions:
Ubuntu
bind9 vulnerabilities
vendor_ubuntu·2017-06-29·CVSS 5.3
CVE-2017-3142 [MEDIUM] bind9 vulnerabilities
Title: bind9 vulnerabilities
Summary: Bind could be made to serve incorrect information or expose sensitive
information over the network.
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
Instructions: After a standard system update you need to restart Bind to make
all the necessary changes.
Red Hat
bind: An error in TSIG authentication can permit unauthorized dynamic updates
vendor_redhat·2017-06-29·CVSS 7.5
CVE-2017-3143 [HIGH] CWE-287 bind: An error in TSIG authentication can permit unauthorized dynamic updates
bind: An error in TSIG authentication can permit unauthorized dynamic updates
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
A flaw was found in the way BIND handled TSIG authentication for dynamic updates. A remote attacker able to communicate with an authoritative BIND server could use this flaw to manipulate the contents of a zone, by forging a valid TSIG or SIG(0) signature for a dynamic update request.
Mitigation: The effects of this vulnerability can be mitig
Debian
CVE-2017-3143: bind9 - An attacker who is able to send and receive messages to an authoritative DNS ser...
vendor_debian·2017·CVSS 7.5
CVE-2017-3143 [HIGH] CVE-2017-3143: bind9 - An attacker who is able to send and receive messages to an authoritative DNS ser...
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
forky: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
sid: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
trixie: resolved (fixed in 1:9.10.3.dfsg.P4-12.4)
GHSA
GHSA-jxfm-jqx8-8h25: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and se
ghsa_unreviewed·2022-05-13
CVE-2017-3143 [MEDIUM] GHSA-jxfm-jqx8-8h25: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and se
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
OSV
CVE-2017-3143: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and se
osv·2019-01-16·CVSS 5.9
CVE-2017-3143 [MEDIUM] CVE-2017-3143: An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and se
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
OSV
bind9 regression
osv·2017-09-18·CVSS 3.7
CVE-2017-3142 [LOW] bind9 regression
bind9 regression
USN-3346-1 fixed vulnerabilities in Bind. The fix for CVE-2017-3142
introduced a regression in the ability to receive an AXFR or IXFR in the
case where TSIG is used and not every message is signed. This update fixes
the problem.
In addition, this update adds the new root zone key signing key (KSK).
Original advisory details:
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
OSV
bind9 vulnerabilities
osv·2017-06-29·CVSS 3.7
CVE-2017-3143 [LOW] bind9 vulnerabilities
bind9 vulnerabilities
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone update requests. An attacker could use this
to improperly perform zone updates. (CVE-2017-3143)
Clément Berthaux discovered that Bind did not correctly check TSIG
authentication for zone transfer requests. An attacker could use this
to improperly transfer entire zones. (CVE-2017-3142)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]
bugzilla·2017-06-30·CVSS 7.5
CVE-2017-3143 [HIGH] CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]
CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]
bugzilla·2017-06-30·CVSS 7.5
CVE-2017-3143 [HIGH] CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]
CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates
bugzilla·2017-06-29·CVSS 7.5
CVE-2017-3143 [HIGH] CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates
CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. A server that relies solely on TSIG or SIG(0) keys with no other address-based ACL protection could be vulnerable to malicious zone content manipulation using this technique.
Workarounds:
The effects of this vulnerability can be mitigated by using Access Control Lists (ACLs) that require both address range validation and use of TSIG authentication in parallel. For information on how to configure this type of compound authentication control, please see:
arXiv
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
arxiv_fulltext·2023-10-04
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
https://faculty.sites.uci.edu/zhouli/research/ Qifan Zhang ,
https://faculty.sites.uci.edu/zhouli/research/ Xuesong Bai ,
https://netsec.ccert.edu.cn/people/lx19 Xiang Li ,
https://netsec.ccert.edu.cn/people/duanhx/ Haixin Duan ,
https://netsec.ccert.edu.cn/people/qli/ Qi Li , and
https://faculty.sites.uci.edu/zhouli/ Zhou Li
Corresponding authors. Most of Xiang Li's work was done when visiting UCI as a project specialist.
https://uci.edu/University of California, Irvine,
https://www.tsinghua.edu.cn/en/Tsinghua University
Zhongguancun Laboratory,
https://www.qcl.edu.cn/Quan Cheng Laboratory
## Abstract
Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache
RFC
Secret Key Transaction Authentication for DNS (TSIG)
rfc·2020-11-01
Secret Key Transaction Authentication for DNS (TSIG)
Internet Engineering Task Force (IETF) F. Dupont
Request for Comments: 8945 ISC
STD: 93 S. Morris
Obsoletes: 2845, 4635 Unaffiliated
Category: Standards Track P. Vixie
ISSN: 2070-1721 Farsight
D. Eastlake 3rd
Futurewei
O. Gudmundsson
Cloudflare
B. Wellington
Akamai
November 2020
Secret Key Transaction Authentication for DNS (TSIG)
Abstract
This document describes a protocol for transaction-level
authentication using shared secrets and one-way hashing. It can be
used to authenticate dynamic updates to a DNS zone as coming from an
approved client or to authenticate responses as coming from an
approved name server.
No recommendation is made here for distributing the shared secrets;
it is expected that a network administrator will statically configure
name servers and clients using so
http://www.securityfocus.com/bid/99337http://www.securitytracker.com/id/1038809https://access.redhat.com/errata/RHSA-2017:1679https://access.redhat.com/errata/RHSA-2017:1680https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03772en_ushttps://kb.isc.org/docs/aa-01503https://security.netapp.com/advisory/ntap-20190830-0003/https://www.debian.org/security/2017/dsa-3904http://www.securityfocus.com/bid/99337http://www.securitytracker.com/id/1038809https://access.redhat.com/errata/RHSA-2017:1679https://access.redhat.com/errata/RHSA-2017:1680https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03772en_ushttps://kb.isc.org/docs/aa-01503https://security.netapp.com/advisory/ntap-20190830-0003/https://www.debian.org/security/2017/dsa-3904
2019-01-16
Published