Use-after-free error in ISC BIND - CVE-2017-3145
Published: January 17, 2018
Vulnerability identifier: #VU10030
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3145
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper sequencing cleanup operations on upstream recursion fetch contexts. A remote attacker can trigger use-after-free error that may lead to assertion failure and cause the BIND name server (named) process to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to improper sequencing cleanup operations on upstream recursion fetch contexts. A remote attacker can trigger use-after-free error that may lead to assertion failure and cause the BIND name server (named) process to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
ISC BIND
Debian Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
bind (Alpine package)
dnsperf
bind
bind-dyndb-ldap
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
Integrated Management Module II (IMM2) for BladeCenter Systems
Debian Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
bind (Alpine package)
dnsperf
bind
bind-dyndb-ldap
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
Integrated Management Module II (IMM2) for BladeCenter Systems
How to mitigate CVE-2017-3145
Update to version 9.9.11-P1, 9.10.6-P1, 9.11.2-P1 or 9.12.0rc2.
bind (Alpine package) - update to 9.10.6_p1-r0
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
dnsperf - addressed in versions 2.1.0.0-8.fc26, 2.1.0.0-11.fc27
bind - addressed in versions 9.11.2-1.P1.fc26, 9.11.2-1.P1.fc27
bind-dyndb-ldap - addressed in versions 11.1-6.fc26, 11.1-8.fc27
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
dnsperf - addressed in versions 2.1.0.0-8.fc26, 2.1.0.0-11.fc27
bind - addressed in versions 9.11.2-1.P1.fc26, 9.11.2-1.P1.fc27
bind-dyndb-ldap - addressed in versions 11.1-6.fc26, 11.1-8.fc27
External References
Related Security Bulletins
- Debian update for bind9
- Denial of service in ISC BIND
- Ubuntu update for Bind
- Ubuntu update for Bind
- Slackware Linux update for bind
- Arch Linux update for bind
- Red Hat update for ISC BIND
- Red Hat update for ISC BIND
- openSUSE update for bind
- SUSE Linux update for bind
- Amazon Linux AMI update for bind
- SUSE Linux update for bind
- Red Hat update for bind
- Red Hat update for bind
- Use-after-free error in bind (Alpine package)
- IBM Flex System Chassis Management Module (CMM) update for ISC BIND
- IBM Integrated Management Module II (IMM2) update for ISC BIND
- Fedora 27 update for bind, bind-dyndb-ldap, dnsperf
- Fedora 26 update for bind, bind-dyndb-ldap, dnsperf