CVE-2017-3145
published 2019-01-16CVE-2017-3145: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an…
PriorityP354high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
27.73%
97.9th percentile
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.11.2.P1-1 (bookworm) | bind9 1:9.11.2.P1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.10.0 – 9.10.6 | — |
| isc | bind | 9.11.0 – 9.11.2 | — |
| isc | bind | 9.4.0 – 9.8.8 | — |
| isc | bind | 9.9.0 – 9.9.11 | — |
| isc | bind9 | >= 0 < 1:9.11.2.P1-1 | 1:9.11.2.P1-1 |
| isc | bind9 | >= 0 < 1:9.11.2.P1-1 | 1:9.11.2.P1-1 |
| isc | bind9 | >= 0 < 1:9.11.2.P1-1 | 1:9.11.2.P1-1 |
| isc | bind9 | >= 0 < 1:9.11.2.P1-1 | 1:9.11.2.P1-1 |
| isc | bind_9 | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerability
vendor_ubuntu·2018-01-17
CVE-2017-3145 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
USN-3535-1 fixed a vulnerability in Bind. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Jayachandran Palanisamy discovered that the Bind resolver incorrectly
handled fetch cleanup sequencing. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bind vulnerability
vendor_ubuntu·2018-01-17
CVE-2017-3145 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Jayachandran Palanisamy discovered that the Bind resolver incorrectly
handled fetch cleanup sequencing. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: Improper fetch cleanup sequencing in the resolver can cause named to crash
vendor_redhat·2018-01-16·CVSS 7.5
CVE-2017-3145 [HIGH] CWE-416 bind: Improper fetch cleanup sequencing in the resolver can cause named to crash
bind: Improper fetch cleanup sequencing in the resolver can cause named to crash
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
A use-after-free flaw leading to denial of service was found in the way BIND internally handled cleanup operations on upstream recursion fetch contexts. A remote attacker could potentially use this flaw to make named, acting as a DNSSEC validating resolver, exit unexpectedly with an assertion failure via a specially crafted DNS request.
Package: bind (Red Hat Enterpri
Debian
CVE-2017-3145: bind9 - BIND was improperly sequencing cleanup operations on upstream recursion fetch co...
vendor_debian·2017·CVSS 7.5
CVE-2017-3145 [HIGH] CVE-2017-3145: bind9 - BIND was improperly sequencing cleanup operations on upstream recursion fetch co...
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
Scope: local
bookworm: resolved (fixed in 1:9.11.2.P1-1)
bullseye: resolved (fixed in 1:9.11.2.P1-1)
forky: resolved (fixed in 1:9.11.2.P1-1)
sid: resolved (fixed in 1:9.11.2.P1-1)
trixie: resolved (fixed in 1:9.11.2.P1-1)
GHSA
GHSA-3hx4-77f4-g7cp: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigg
ghsa_unreviewed·2022-05-13
CVE-2017-3145 [HIGH] CWE-416 GHSA-3hx4-77f4-g7cp: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigg
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
OSV
CVE-2017-3145: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigg
osv·2019-01-16·CVSS 7.5
CVE-2017-3145 [HIGH] CVE-2017-3145: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigg
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3145 bind: Improper sequencing during cleanup can lead to use-after-free error, causinga crash in named [fedora-all]
bugzilla·2018-01-17·CVSS 7.5
CVE-2017-3145 [HIGH] CVE-2017-3145 bind: Improper sequencing during cleanup can lead to use-after-free error, causinga crash in named [fedora-all]
CVE-2017-3145 bind: Improper sequencing during cleanup can lead to use-after-free error, causinga crash in named [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2017-3145 bind: Improper fetch cleanup sequencing in the resolver can cause named to crash
bugzilla·2018-01-16·CVSS 7.5
CVE-2017-3145 [HIGH] CVE-2017-3145 bind: Improper fetch cleanup sequencing in the resolver can cause named to crash
CVE-2017-3145 bind: Improper fetch cleanup sequencing in the resolver can cause named to crash
Improper sequencing during cleanup operations of upstream recursion fetch contexts in BIND can lead to a use-after-free error, triggering an assertion failure and crash in named.
Affected BIND versions acting as DNSSEC validating resolvers are currently known to crash with an assertion failure in netaddr.c due to this bug.
External References:
https://kb.isc.org/article/AA-01542
Upstream Patches:
ftp://ftp.isc.org/isc/bind9/9.9.11-P1/patches/CVE-2017-3145
ftp://ftp.isc.org/isc/bind9/9.10.6-P1/patches/CVE-2017-3145
ftp://ftp.isc.org/isc/bind9/9.11.2-P1/patches/CVE-2017-3145
Discussion:
Created bind tracking bugs for this issue:
Affects: fedora-all [bug 1535307]
---
Acknowledgments:
Nam
http://www.securityfocus.com/bid/102716http://www.securitytracker.com/id/1040195https://access.redhat.com/errata/RHSA-2018:0101https://access.redhat.com/errata/RHSA-2018:0102https://access.redhat.com/errata/RHSA-2018:0487https://access.redhat.com/errata/RHSA-2018:0488https://kb.isc.org/docs/aa-01542https://lists.debian.org/debian-lts-announce/2018/01/msg00029.htmlhttps://security.netapp.com/advisory/ntap-20180117-0003/https://supportportal.juniper.net/s/article/2018-07-Security-Bulletin-SRX-Series-Vulnerabilities-in-ISC-BIND-namedhttps://www.debian.org/security/2018/dsa-4089http://www.securityfocus.com/bid/102716http://www.securitytracker.com/id/1040195https://access.redhat.com/errata/RHSA-2018:0101https://access.redhat.com/errata/RHSA-2018:0102https://access.redhat.com/errata/RHSA-2018:0487https://access.redhat.com/errata/RHSA-2018:0488https://kb.isc.org/docs/aa-01542https://lists.debian.org/debian-lts-announce/2018/01/msg00029.htmlhttps://security.netapp.com/advisory/ntap-20180117-0003/https://supportportal.juniper.net/s/article/2018-07-Security-Bulletin-SRX-Series-Vulnerabilities-in-ISC-BIND-namedhttps://www.debian.org/security/2018/dsa-4089
2019-01-16
Published