5.9

CVE-2017-3135

Combination of DNS64 and RPZ Can Lead to Crash

Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind Version 9.9.3
Isc ≫ Bind Version 9.9.3 Update s1
Isc ≫ Bind Version 9.9.8
Isc ≫ Bind Version 9.9.9 Update p5
Isc ≫ Bind Version 9.9.9 Update s7
Isc ≫ Bind Version 9.9.10 Update beta1
Isc ≫ Bind Version 9.10.0
Isc ≫ Bind Version 9.10.4 Update p1
Isc ≫ Bind Version 9.10.4 Update p2
Isc ≫ Bind Version 9.10.4 Update p3
Isc ≫ Bind Version 9.10.4 Update p4
Isc ≫ Bind Version 9.10.4 Update p5
Isc ≫ Bind Version 9.10.5 Update beta1
Isc ≫ Bind Version 9.11.0
Isc ≫ Bind Version 9.11.0 Update p1
Isc ≫ Bind Version 9.11.0 Update p2
Isc ≫ Bind Version 9.11.1 Update beta1
Netapp ≫ Data Ontap Edge Version -
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.24% 0.968
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
ISC 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://security.netapp.com/advisory/ntap-20180926-0005/
Third Party Advisory
https://security.gentoo.org/glsa/201708-01
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0276.html
Third Party Advisory
http://www.securityfocus.com/bid/96150
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037801
Third Party Advisory
VDB Entry
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03747en_us
Third Party Advisory
https://kb.isc.org/docs/aa-01453
Vendor Advisory
https://www.debian.org/security/2017/dsa-3795
Third Party Advisory