CVE-2017-3143

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/01/2019
Last modified:
03/10/2019

Description

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.4.0 (including) 9.8.8 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.9.0 (including) 9.9.10 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.10.0 (including) 9.10.5 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.11.0 (including) 9.11.1 (including)
cpe:2.3:a:isc:bind:9.9.0:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.3:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.10:s2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:s2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.1:p1:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*