Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.146587
Categoría:Denial of Service
Título:ISC BIND DoS Vulnerability (CVE-2017-3137) - Linux
Resumen:ISC BIND is prone to a denial of service (DoS) vulnerability.
Descripción:Summary:
ISC BIND is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
Mistaken assumptions about the ordering of records in the answer
section of a response containing CNAME or DNAME resource records could lead to a situation in
which named would exit with an assertion failure when processing a response in which records
occurred in an unusual order.

Vulnerability Impact:
A server which is performing recursion can be forced to exit with
an assertion failure if it can be caused to receive a response containing CNAME or DNAME resource
records with certain ordering. An attacker can cause a denial of service by exploiting this
condition. Recursive resolvers are at highest risk, but authoritative servers are theoretically
vulnerable if they perform recursion.

Affected Software/OS:
BIND 9.9.9-P6, 9.9.10b1 through 9.9.10rc1, 9.10.4-P6, 9.10.5b1
through 9.10.5rc1, 9.11.0-P3, 9.11.1b1 through 9.11.1rc1 and 9.9.9-S8.

Solution:
Update to version 9.9.9-P8, 9.9.10rc3, 9.10.4-P8, 9.10.5rc3,
9.11.0-P5, 9.11.1rc3, 9.9.9-S10 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-3137
BugTraq ID: 97651
http://www.securityfocus.com/bid/97651
Debian Security Information: DSA-3854 (Google Search)
https://www.debian.org/security/2017/dsa-3854
https://security.gentoo.org/glsa/201708-01
RedHat Security Advisories: RHSA-2017:1095
https://access.redhat.com/errata/RHSA-2017:1095
RedHat Security Advisories: RHSA-2017:1105
https://access.redhat.com/errata/RHSA-2017:1105
RedHat Security Advisories: RHSA-2017:1582
https://access.redhat.com/errata/RHSA-2017:1582
RedHat Security Advisories: RHSA-2017:1583
https://access.redhat.com/errata/RHSA-2017:1583
http://www.securitytracker.com/id/1038258
http://www.securitytracker.com/id/1040195
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.