← Back

CVE-2017-3138

nvd nist
Published: Jan 16, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.6 / Impact: 3.6
Source: NVD

Description

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.

Affected (36)

1 product
Bind
3 products
Data Ontap Edge
Element Software
Oncommand Balance
1 product
Debian Linux
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Isc
Version 9.10.4
Version 9.10.4 p1
Version 9.10.4 p2
Version 9.10.4 p3
Version 9.10.4 p4
Version 9.10.4 p5
Version 9.10.4 p6
Version 9.10.4 p7
Version 9.10.5 b1
Version 9.10.5 rc1
Version 9.10.5 rc2
Version 9.11.0
Version 9.11.0 p1
Version 9.11.0 p2
Version 9.11.0 p3
Version 9.11.0 p4
Version 9.11.1 b1
Version 9.11.1 rc1
Version 9.11.1 rc2
Version 9.9.10 beta1
Version 9.9.10 rc1
Version 9.9.10 rc2
Version 9.9.9
Version 9.9.9 p1
Version 9.9.9 p2
Version 9.9.9 p3
Version 9.9.9 p4
Version 9.9.9 p5
Version 9.9.9 p6
Version 9.9.9 p7
Version 9.9.9 s1
Version 9.9.9 s7
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

References (12)

Source: security-officer@isc.org
Third Party AdvisoryVDB Entry
Source: security-officer@isc.org
Third Party AdvisoryVDB Entry
Source: security-officer@isc.org
Vendor Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.