← All CVEs

CVE-2017-3140

low · 3.7

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

3.7
CVSS
12.2%
EPSS (exploit prob.)
96th
EPSS percentile
2019-01-16
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
iscbind>= 9.11.0, <= 9.11.1
iscbind9.9.10
iscbind9.9.10
iscbind9.10.5
iscbind9.10.5
netappdata_ontap_edgeall versions
netappelement_softwareall versions
netapponcommand_balanceall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-3140