CVE-2017-3138

named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:isc:bind:9.9.9:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p3:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p4:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p5:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p6:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:p7:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.9:s7:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.10:beta1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.10:rc1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.9.10:rc2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p3:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p4:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p5:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p6:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.4:p7:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:b1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:rc1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.10.5:rc2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.0:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.0:p1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.0:p2:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.0:p3:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.0:p4:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.1:b1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.1:rc1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.1:rc2:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-01-16 20:29

Updated : 2024-02-04 20:03


NVD link : CVE-2017-3138

Mitre link : CVE-2017-3138

CVE.ORG link : CVE-2017-3138


JSON object : View

Products Affected

debian

  • debian_linux

netapp

  • element_software
  • oncommand_balance
  • data_ontap_edge

isc

  • bind
CWE
CWE-617

Reachable Assertion