Combination of DNS64 and RPZ Can Lead to Crash
Vulnerability Description
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3135
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ISC would like to thank Ramesh Damodaran(Infoblox) and Aliaksandr Shubnik (Infoblox) for reporting the issue and assisting us in the investigation.
References
- https://security.gentoo.org/glsa/201708-01
- http://rhn.redhat.com/errata/RHSA-2017-0276.html
- https://security.netapp.com/advisory/ntap-20180926-0005/
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03747en_us
- http://www.securityfocus.com/bid/96150
- http://www.securitytracker.com/id/1037801
- https://www.debian.org/security/2017/dsa-3795
- https://kb.isc.org/docs/aa-01453
More from ISC
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.