CVE-2017-3140 describes a denial-of-service vulnerability in BIND versions 9.9.10, 9.10.5, and 9.11.0 through 9.11.1, as well as their S1 variants, and related NetApp products. When BIND is configured with Response Policy Zones (RPZ), specific rule types can cause an endless loop during query processing. This medium-severity flaw (CVSS 5.9) has a high impact on availability and a high attack complexity, as it requires specific RPZ configurations to be exploited remotely without user interaction. There is no evidence of active exploitation, public exploit code, or Metasploit modules, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.11.0, <= 9.11.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.10:*:*:*:*:*:*:* | ||
9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.10:s1:*:*:*:*:*:* | ||
9.10.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.10.5:*:*:*:*:*:*:* | ||
9.10.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.10.5:s1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.