Assertion failure in ISC BIND - CVE-2017-3138
Published: November 28, 2018
Vulnerability details
The vulnerability exists due to named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc.. A remote attacker can send some versions of named a null command string, trigger a REQUIRE assertion failure and cause the service to crash.
Affected software
Gentoo Linux
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
bind9 (Debian package)
bind (Alpine package)
bind99
bind
Dell EMC Unisphere Central
How to mitigate CVE-2017-3138
bind9 (Debian package) - update to 1:9.9.5.dfsg-9+deb8u11
bind (Alpine package) - update to 9.10.4_p8-r0
Dell EMC Unisphere Central - update to 4.0.7
bind99 - addressed in versions 9.9.9-4.P8.fc24, 9.9.9-4.P8.fc25, 9.9.9-5.P8.fc26
bind - addressed in versions 9.10.4-3.P8.fc24, 9.10.4-4.P8.fc25, 9.11.0-7.P5.fc26
External References
Related Security Bulletins
- Arch Linux update for bind
- Gentoo update for BIND
- Slackware Linux update for bind
- Debian update for bind9
- OpenSUSE Linux update for bind
- SUSE Linux update for bind
- SUSE Linux update for bind
- Assertion failure in bind (Alpine package)
- Multiple vulnerabilities in Dell EMC Unisphere Central
- Fedora 25 update for bind
- Fedora 24 update for bind
- Fedora 26 update for bind
- Fedora 25 update for bind99
- Fedora 24 update for bind99
- Fedora 26 update for bind99