4.3
CVSSv2

CVE-2017-3140

Published: 16/01/2019 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.9.10

isc bind 9.10.5

isc bind

netapp oncommand balance -

netapp element software -

netapp data ontap edge -

Vendor Advisories

A denial of service flaw was found in the way BIND handled processing of NSDNAME and NSIP rules A remote attacker could use this flaw to make named enter an infinite loop by sending a specially crafted query, thus resulting in denial-of-service ...
A security issue has been found the Bind named DNS server < 9111P1, leading to a denial of service A remote attacker can make a vulnerable server configured to use a RPZ containing NSDNAME or NSIPpolicy rules enter an endless loop, querying the same sets of authoritative servers repeatedly, by sending a crafted query ...