Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3136


A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.0 -> 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0 -> 9.11.0-P3, 9.11.1b1->9.11.1rc1, 9.9.3-S1 -> 9.9.9-S8.


Published

2019-01-16T20:29:00.313

Last Modified

2024-11-21T03:24:54.430

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application isc bind ≤ 9.8.8 Yes
Application isc bind ≤ 9.9.9 Yes
Application isc bind ≤ 9.10.4 Yes
Application isc bind 9.8.0 Yes
Application isc bind 9.9.0 Yes
Application isc bind 9.9.0 Yes
Application isc bind 9.9.0 Yes
Application isc bind 9.9.0 Yes
Application isc bind 9.9.0 Yes
Application isc bind 9.9.0 Yes
Application isc bind 9.9.3 Yes
Application isc bind 9.9.3 Yes
Application isc bind 9.9.10 Yes
Application isc bind 9.9.10 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.4 Yes
Application isc bind 9.10.5 Yes
Application isc bind 9.10.5 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.0 Yes
Application isc bind 9.11.1 Yes
Application isc bind 9.11.1 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_eus 7.3 Yes
Operating System redhat enterprise_linux_server_eus 7.4 Yes
Operating System redhat enterprise_linux_server_eus 7.5 Yes
Operating System redhat enterprise_linux_server_eus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Application netapp data_ontap_edge - Yes
Application netapp element_software - Yes
Application netapp oncommand_balance - Yes
Operating System debian debian_linux 8.0 Yes

References