← Back

CVE-2017-3142

nvd nist
Published: Jan 16, 2019Modified: Nov 21, 2024

JSON object

Loading...
3.7
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

Affected (28)

1 product
Bind
6 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Server Tus
Enterprise Linux Workstation
1 product
Debian Linux
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Isc
From 9.10.0 to 9.10.5
From 9.11.0 to 9.11.1
From 9.4.0 to 9.8.8
From 9.9.0 to 9.9.10
Version 9.10.5 p1
Version 9.10.5 s1
Version 9.10.5 s2
Version 9.11.1 p1
Version 9.9.0 p1
Version 9.9.10 s2
Version 9.9.3 s1
Configuration B
15 vulnerable
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0

References (16)

Source: security-officer@isc.org
Third Party AdvisoryVDB Entry
Source: security-officer@isc.org
Third Party AdvisoryVDB Entry
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Vendor Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.