SB2017042532 - Assertion failure in bind (Alpine package)



SB2017042532 - Assertion failure in bind (Alpine package)

Published: April 25, 2017

Security Bulletin ID SB2017042532
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Assertion failure (CVE-ID: CVE-2017-3138)

The vulnerability allows a remote authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc.. A remote attacker can send some versions of named a null command string, trigger a REQUIRE assertion failure and cause the service to crash.


Remediation

Install update from vendor's website.