Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-3854-1 Critical: Bind9 Denial-Of-Service Flaws

debian
Calendar Grey May 14, 2017
Debian Logo
Update your Bind9 software as per Debian: DSA-3854-2 to address potential denial-of-service flaws. Discover additional details.
Several vulnerabilities were discovered in BIND, a DNS server implementation

Summary

CVE-2017-3136

Oleg Gorokhov of Yandex discovered that BIND does not properly
handle certain queries when using DNS64 with the "break-dnssec yes;"
option, allowing a remote attacker to cause a denial-of-service.

CVE-2017-3137

It was discovered that BIND makes incorrect assumptions about the
ordering of records in the answer section of a response containing
CNAME or DNAME resource records, leading to situations where BIND
exits with an assertion failure. An attacker can take advantage of
this condition to cause a denial-of-service.

CVE-2017-3138

Mike Lalumiere of Dyn, Inc. discovered that BIND can exit with a
REQUIRE assertion failure if it receives a null command string on
its control channel. Note that the fix applied in Debian is only
applied as a hardening measure. Details about the issue can be found
at https://kb.isc.org/docs/aa-01471 .

For the stable distribution (jessie), these problems have been fixed in
version 1:9.9.5.dfsg-9+deb8u11.

For th...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9
CVE ID: CVE-2017-3136 CVE-2017-3137 CVE-2017-3138

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here