CVE-2017-3142

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-3142
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-3142.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-3142
Related
Published
2019-01-16T20:29:00Z
Modified
2024-10-12T02:44:20.121858Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providing an AXFR of a zone to an unauthorized recipient or accepting bogus NOTIFY packets. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

References

Affected packages

Alpine:v3.3 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.10.4_p8-r1

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p4-r0
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p4-r0
9.10.4_p5-r0
9.10.4_p6-r0
9.10.4_p8-r0

Alpine:v3.4 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.10.4_p8-r1

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p4-r0
9.10.4_p5-r0
9.10.4_p6-r0
9.10.4_p8-r0

Alpine:v3.5 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.10.4_p8-r1

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p1-r1
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p3-r1
9.10.4_p4-r0
9.10.4_p5-r0
9.10.4_p5-r1
9.10.4_p6-r0
9.10.4_p8-r0

Alpine:v3.6 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.11.1_p1-r1

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p1-r1
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p3-r1
9.10.4_p4-r0
9.10.4_p5-r0
9.11.0_p2-r0
9.11.0_p2-r1
9.11.0_p3-r0
9.11.0_p5-r0
9.11.0_p5-r1
9.11.1_p1-r0

Alpine:v3.7 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.11.3-r0

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p1-r1
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p3-r1
9.10.4_p4-r0
9.10.4_p5-r0
9.11.0_p2-r0
9.11.0_p2-r1
9.11.0_p3-r0
9.11.0_p5-r0
9.11.0_p5-r1
9.11.1-r0
9.11.1_p1-r0
9.11.1_p2-r0
9.11.1_p2-r1
9.11.1_p2-r2
9.11.2-r0
9.11.2-r1
9.11.2_p1-r0

Debian:11 / bind9

Package

Name
bind9
Purl
pkg:deb/debian/bind9?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.10.3.dfsg.P4-12.4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / bind9

Package

Name
bind9
Purl
pkg:deb/debian/bind9?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.10.3.dfsg.P4-12.4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / bind9

Package

Name
bind9
Purl
pkg:deb/debian/bind9?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.10.3.dfsg.P4-12.4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/isc-projects/bind9