Assertion failure in ISC BIND - CVE-2017-3138

 

Assertion failure in ISC BIND - CVE-2017-3138

Published: November 28, 2018


Vulnerability identifier: #VU16151
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3138
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc.. A remote attacker can send some versions of named a null command string, trigger a REQUIRE assertion failure and cause the service to crash.


Affected software

ISC BIND
Gentoo Linux
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
bind9 (Debian package)
bind (Alpine package)
bind99
bind
Dell EMC Unisphere Central

How to mitigate CVE-2017-3138

The vulnerability has been addressed in the versions 9.9.9-P8, 9.10.4-P8, 9.11.0-P5.

ISC BIND - addressed in versions 9.9.9-P8, 9.10.4-P8, 9.11.0-P5
bind9 (Debian package) - update to 1:9.9.5.dfsg-9+deb8u11
bind (Alpine package) - update to 9.10.4_p8-r0
Dell EMC Unisphere Central - update to 4.0.7
bind99 - addressed in versions 9.9.9-4.P8.fc24, 9.9.9-4.P8.fc25, 9.9.9-5.P8.fc26
bind - addressed in versions 9.10.4-3.P8.fc24, 9.10.4-4.P8.fc25, 9.11.0-7.P5.fc26

External References

Related Security Bulletins