CVE-2017-3137: A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order.
A server which is performing recursion can be forced to exit with an assertion failure if it can be caused to receive a response containing CNAME or DNAME resource records with certain ordering. An attacker can cause a denial of service by exploiting this condition. Recursive resolvers are at highest risk but authoritative servers are theoretically vulnerable if they perform recursion.
External References:
https://kb.isc.org/article/AA-01466
Other sources
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3137?
CVE-2017-3137 is classified as a high-severity vulnerability due to its potential to cause assertion failures leading to denial-of-service.
How do I fix CVE-2017-3137?
To fix CVE-2017-3137, upgrade to a patched version of BIND specified in the remediation section, such as 9.11.5.P4+dfsg-5.1+deb10u7 or later.
What systems are affected by CVE-2017-3137?
CVE-2017-3137 affects various versions of the BIND DNS server, particularly those below the patched versions mentioned in the remediation section.
What impact does CVE-2017-3137 have on my server?
The impact of CVE-2017-3137 is that it may cause your server to crash or become unresponsive due to assertion failures when processing DNS responses.
Is there a workaround for CVE-2017-3137?
There is no known workaround for CVE-2017-3137, so upgrading to a secure version is the recommended action.