Improper input validation in ISC BIND - CVE-2017-3140
Published: June 15, 2017 / Updated: June 15, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing Response Policy Zones (RPZ) rules, when NSDNAME or NSIP policy rules are used. A remote attacker can trigger the affected server to enter an endless loop and repeatedly query a set of authoritative nameservers.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service attack.
Affected software
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
bind (Alpine package)
dnsperf
dhcp
bind99
bind
bind-dyndb-ldap
How to mitigate CVE-2017-3140
dnsperf - addressed in versions 2.1.0.0-3.fc24, 2.1.0.0-3.fc25
dhcp - addressed in versions 4.3.5-3.fc25, 4.3.5-7.fc26
bind99 - addressed in versions 9.9.10-1.P2.fc25, 9.9.10-1.P2.fc26
bind - addressed in versions 9.10.5-2.P2.fc24, 9.10.5-2.P2.fc25, 9.11.1-1.P1.fc26
bind-dyndb-ldap - addressed in versions 10.1-2.fc24, 10.1-2.fc25
External References
Related Security Bulletins
- Remote DoS when processing RPZ rules in ISC BIND
- Arch Linux update for bind
- Slackware Linux update for bind
- Gentoo update for BIND
- Improper input validation in bind (Alpine package)
- Fedora 26 update for bind
- Fedora 24 update for bind, bind-dyndb-ldap, dnsperf
- Fedora 25 update for bind, bind-dyndb-ldap, dnsperf
- Fedora 25 update for bind99, dhcp
- Fedora 26 update for bind99, dhcp