CVE-2017-3137 is a high-severity vulnerability affecting multiple versions of BIND, including those distributed by Debian, ISC, NetApp, and Red Hat. It stems from incorrect assumptions in BIND's handling of CNAME or DNAME records in DNS responses, leading to an assertion failure and denial of service. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network without authentication, allowing an attacker to crash the BIND service. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:p6:*:*:*:*:*:* | ||
9.9.9CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.9:s8:*:*:*:*:*:* | ||
9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.10:beta1:*:*:*:*:*:* | ||
9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.10:rc1:*:*:*:*:*:* | ||
9.10.4CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.10.4:p6:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.