CVE-2017-3139: High severity red hat enterprise linux server vulnerability
Published May 3, 2017
·Updated
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
Affected Software
8 affected componentsFixes available
debian/bind9
1:9.11.5.P4+dfsg-5.1+deb10u71:9.11.5.P4+dfsg-5.1+deb10u91:9.16.44-1~deb11u11:9.18.19-1~deb12u11:9.19.17-1
redhat Enterprise Linux Server Aus=6.2
redhat Enterprise Linux Server Aus=6.4
redhat Enterprise Linux Server Aus=6.5
redhat Enterprise Linux Server Aus=6.6
redhat Enterprise Linux Server Eus=6.7
redhat Enterprise Linux Server Tus=6.5
redhat Enterprise Linux Server Tus=6.6
Event History
May 3, 2017
Data Sourced
via Red Hat·04:06 PM
DescriptionSeverityAffected Software
Apr 9, 2019
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3139?
CVE-2017-3139 has a severity rating of moderate due to its potential to cause denial of service.
2
How do I fix CVE-2017-3139?
To fix CVE-2017-3139, upgrade to a patched version of the BIND software as listed in the advisory.
3
What software is affected by CVE-2017-3139?
CVE-2017-3139 affects various versions of BIND, particularly those on Debian and Red Hat Enterprise Linux.
4
Can CVE-2017-3139 be exploited remotely?
Yes, CVE-2017-3139 can be exploited remotely through specially crafted DNS responses.
5
What are the symptoms of an attack exploiting CVE-2017-3139?
An attack exploiting CVE-2017-3139 may cause the BIND service to exit unexpectedly due to an assertion failure.