CVE-2017-3145

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
16/01/2019
Last modified:
21/06/2023

Description

BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.4.0 (including) 9.8.8 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.9.0 (including) 9.9.11 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.10.0 (including) 9.10.6 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.11.0 (including) 9.11.2 (including)
cpe:2.3:a:isc:bind:9.9.3:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.11:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.6:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.12.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.12.0:b1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.12.0:b2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.12.0:rc1:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*