CVE-2017-3141

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-3141
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-3141.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-3141
Related
Published
2019-01-16T20:29:00Z
Modified
2025-02-14T10:18:09.871842Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.

References

Affected packages

Alpine:v3.6 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.11.3-r0

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p1-r1
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p3-r1
9.10.4_p4-r0
9.10.4_p5-r0
9.11.0_p2-r0
9.11.0_p2-r1
9.11.0_p3-r0
9.11.0_p5-r0
9.11.0_p5-r1
9.11.1_p1-r0
9.11.1_p1-r1
9.11.1_p1-r2
9.11.2_p1-r0

Alpine:v3.7 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.11.3-r0

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p1-r1
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p3-r1
9.10.4_p4-r0
9.10.4_p5-r0
9.11.0_p2-r0
9.11.0_p2-r1
9.11.0_p3-r0
9.11.0_p5-r0
9.11.0_p5-r1
9.11.1-r0
9.11.1_p1-r0
9.11.1_p2-r0
9.11.1_p2-r1
9.11.1_p2-r2
9.11.2-r0
9.11.2-r1
9.11.2_p1-r0

Git / github.com/isc-projects/bind9

Affected versions

v9.*

v9.11.0
v9.11.1
v9.11.1b1
v9.11.1rc1
v9.11.1rc2
v9.11.1rc3
v9.2.6
v9.2.9
v9.2.9b1
v9.2.9rc1
v9.5.0a1
v9.5.0a2
v9.5.0a3
v9.5.0a4
v9.5.0a5
v9.9.0
v9.9.1
v9.9.10
v9.9.10b1
v9.9.10rc1
v9.9.10rc2
v9.9.10rc3
v9.9.2b1
v9.9.2rc1
v9.9.3
v9.9.3b1
v9.9.3b2
v9.9.3rc1
v9.9.3rc2
v9.9.4
v9.9.4b1
v9.9.4rc1
v9.9.4rc2
v9.9.5
v9.9.5b1
v9.9.5rc1
v9.9.5rc2
v9.9.6
v9.9.6b1
v9.9.6b2
v9.9.6rc1
v9.9.6rc2
v9.9.7
v9.9.7b1
v9.9.7rc1
v9.9.7rc2
v9.9.8
v9.9.8b1
v9.9.8rc1
v9.9.9
v9.9.9b1
v9.9.9b2
v9.9.9rc1