Security restrictions bypass in ISC BIND - CVE-2017-3143

 

Security restrictions bypass in ISC BIND - CVE-2017-3143

Published: June 30, 2017 / Updated: June 30, 2017


Vulnerability identifier: #VU7258
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3143
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to an error in TSIG authentication of AXFR requests. A remote attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name can send specially crafted request packet, manipulate the malicious zone content and accept unauthorized dynamic updates.

Affected software

ISC BIND
Amazon Linux AMI
Debian Linux
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
Fedora
bind (Alpine package)
dnsperf
dhcp
bind99
bind
bind-dyndb-ldap
Dell EMC Unisphere Central

How to mitigate CVE-2017-3143

The vulnerability is addressed in the following versions:
9.9.10-P2, 9.10.5-P2, 9.11.1-P2, 9.9.10-S3, 9.10.5-S3.

bind (Alpine package) - update to 9.10.4_p8-r1
dnsperf - addressed in versions 2.1.0.0-3.fc24, 2.1.0.0-3.fc25
Dell EMC Unisphere Central - update to 4.0.7
dhcp - addressed in versions 4.3.4-4.fc24, 4.3.5-3.fc25, 4.3.5-7.fc26
bind99 - addressed in versions 9.9.10-1.P2.fc25, 9.9.10-1.P2.fc26, 9.9.10-2.P3.fc24
bind - addressed in versions 9.10.5-2.P2.fc24, 9.10.5-2.P2.fc25, 9.11.1-2.P2.fc26
bind-dyndb-ldap - addressed in versions 10.1-2.fc24, 10.1-2.fc25

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins