SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Generic)  >   BIND Vendors:   ISC (Internet Software Consortium)
(Oracle Issues Fix for Oracle Linux) BIND DNS64 State Error Lets Remote Users Cause the Target Service to Crash
SecurityTracker Alert ID:  1038333
SecurityTracker URL:  http://securitytracker.com/id/1038333
CVE Reference:   CVE-2017-3136   (Links to External Site)
Date:  Apr 20 2017
Impact:   Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 9.8.0 - 9.8.8-P1, 9.9.0 - 9.9.9-P6, 9.9.10b1 - 9.9.10rc1, 9.10.0 - 9.10.4-P6, 9.10.5b1 - 9.10.5rc1, 9.11.0 - 9.11.0-P3, 9.11.1b1 - 9.11.1rc1, 9.9.3-S1 - 9.9.9-S8
Description:   A vulnerability was reported in BIND. A remote user can cause the target service to crash.

A remote user can supply a specially crafted query to trigger a flaw in the DNS64 feature and cause the target service to crash.

Systems configured to use DNS64 and configured with the "break-dnssec yes;" option are affected.

Oleg Gorokhov of Yandex reported this vulnerability.

Impact:   A remote user can cause the target service to crash.
Solution:   Oracle has issued a fix.

The Oracle Linux advisory is available at:

http://linux.oracle.com/errata/ELSA-2017-1105.html

Vendor URL:  linux.oracle.com/errata/ELSA-2017-1105.html (Links to External Site)
Cause:   State error
Underlying OS:  Linux (Oracle)
Underlying OS Comments:  6

Message History:   This archive entry is a follow-up to the message listed below.
Apr 13 2017 BIND DNS64 State Error Lets Remote Users Cause the Target Service to Crash



 Source Message Contents

Date:  Thu, 20 Apr 2017 07:54:42 -0700
Subject:  [El-errata] ELSA-2017-1105 Important: Oracle Linux 6 bind security update

Oracle Linux Security Advisory ELSA-2017-1105

http://linux.oracle.com/errata/ELSA-2017-1105.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
bind-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-chroot-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-devel-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-libs-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-sdb-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-utils-9.8.2-0.62.rc1.el6_9.1.i686.rpm

x86_64:
bind-9.8.2-0.62.rc1.el6_9.1.x86_64.rpm
bind-chroot-9.8.2-0.62.rc1.el6_9.1.x86_64.rpm
bind-devel-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-devel-9.8.2-0.62.rc1.el6_9.1.x86_64.rpm
bind-libs-9.8.2-0.62.rc1.el6_9.1.i686.rpm
bind-libs-9.8.2-0.62.rc1.el6_9.1.x86_64.rpm
bind-sdb-9.8.2-0.62.rc1.el6_9.1.x86_64.rpm
bind-utils-9.8.2-0.62.rc1.el6_9.1.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/bind-9.8.2-0.62.rc1.el6_9.1.src.rpm



Description of changes:

[32:9.8.2-0.62.rc1.1]
- Fix CVE-2017-3136 (ISC change 4575)
- Fix CVE-2017-3137 (ISC change 4578)


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2017, SecurityGlobal.net LLC