CVE-2017-3135

Description

Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
34.413

Associated Vulnerability

VulnerabilityOS Platform
Internet Domain Name Server (USN-3172-1) bind9_9.10.3.dfsg.P4-10.1ubuntu1.3_i386.debLinux
Internet Domain Name Server (USN-3172-1) bind9_9.10.3.dfsg.P4-10.1ubuntu1.3_amd64.debLinux
bind9 security update(DSA-3795-1) bind9_9.9.5.dfsg-9+deb8u10_i386.debLinux
bind9 security update(DSA-3795-1) bind9_9.9.5.dfsg-9+deb8u10_amd64.debLinux
bind9 security update(DSA-3795-1) bind9_9.9.5.dfsg-9+deb8u10_kfreebsd-i386.debLinux
bind9 security update(DSA-3795-1) bind9_9.9.5.dfsg-9+deb8u10_kfreebsd-amd64.debLinux
NULL Pointer Dereference Vulnerability (CVE-2017-3135)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234