CVE-2017-3140: An error processing RPZ rules can cause named to loop endlessly after handling a query
Published Jan 16, 2019
·Updated
If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.
Affected Software
8 affected components
ISC BIND>=9.11.0<=9.11.1
ISC BIND=9.9.10
ISC BIND=9.9.10-s1
ISC BIND=9.10.5
ISC BIND=9.10.5-s1
NetApp Data Ontap Edge
NetApp Element Software
NetApp OnCommand Balance
Remediation
Information
Upgrade to the patched release most closely related to your current version of BIND. These can all be downloaded from http://www.isc.org/downloads.
BIND 9 version 9.9.10-P1
BIND 9 version 9.10.5-P1
BIND 9 version 9.11.1-P1
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
BIND 9 version 9.9.10-S2
BIND 9 version 9.10.5-S2
Event History
Jan 16, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2017-3140?
CVE-2017-3140 is a vulnerability in BIND, affecting versions 9.9.10, 9.10.5, and 9.11.0 to 9.11.1.
2
What is the severity of CVE-2017-3140?
CVE-2017-3140 has a severity rating of 5.9, which is considered medium.
3
How does CVE-2017-3140 affect BIND?
CVE-2017-3140 can cause BIND to enter an endless loop while handling a query, if named is configured to use Response Policy Zones (RPZ).
4
Which software versions are affected by CVE-2017-3140?
CVE-2017-3140 affects BIND versions 9.9.10, 9.10.5, and 9.11.0 to 9.11.1.
5
How can I fix CVE-2017-3140?
To fix CVE-2017-3140, it is recommended to upgrade to a patched version of BIND.