7.5

CVE-2017-3135

Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.

Data is provided by the National Vulnerability Database (NVD)
IscBind Version9.9.3
IscBind Version9.9.3 Updates1
IscBind Version9.9.8
IscBind Version9.9.9 Updatep5
IscBind Version9.9.9 Updates7
IscBind Version9.9.10 Updatebeta1
IscBind Version9.10.0
IscBind Version9.10.4 Updatep1
IscBind Version9.10.4 Updatep2
IscBind Version9.10.4 Updatep3
IscBind Version9.10.4 Updatep4
IscBind Version9.10.4 Updatep5
IscBind Version9.10.5 Updatebeta1
IscBind Version9.11.0
IscBind Version9.11.0 Updatep1
IscBind Version9.11.0 Updatep2
IscBind Version9.11.1 Updatebeta1
NetappData Ontap Edge Version-
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 35.73% 0.967
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
security-officer@isc.org 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.