Executive Summary

Informations
Name CVE-2012-3817 First vendor Publication 2012-07-25
Vendor Cve Last vendor Modification 2018-10-30

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3817

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-20 Improper Input Validation

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:17785
 
Oval ID: oval:org.mitre.oval:def:17785
Title: USN-1518-1 -- bind9 vulnerability
Description: Bind could be made to crash if it received specially crafted network traffic.
Family: unix Class: patch
Reference(s): USN-1518-1
CVE-2012-3817
Version: 5
Platform(s): Ubuntu 12.04
Ubuntu 11.10
Ubuntu 11.04
Ubuntu 10.04
Product(s): bind9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18449
 
Oval ID: oval:org.mitre.oval:def:18449
Title: DSA-2517-1 bind9 - denial of service
Description: Einar Lonn discovered that under certain conditions bind9, a DNS server, may use cached data before initialisation. As a result, an attacker can trigger an assertion failure on servers under high query load that do DNSSEC validation.
Family: unix Class: patch
Reference(s): DSA-2517-1
CVE-2012-3817
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): bind9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:19849
 
Oval ID: oval:org.mitre.oval:def:19849
Title: HP-UX Running BIND, Remote Denial of Service (DoS), Authentication Bypass
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: vulnerability
Reference(s): CVE-2012-3817
Version: 11
Platform(s): HP-UX 11
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:20335
 
Oval ID: oval:org.mitre.oval:def:20335
Title: VMware security updates for vSphere API and ESX Service Console
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: vulnerability
Reference(s): CVE-2012-3817
Version: 4
Platform(s): VMWare ESX Server 4.1
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21429
 
Oval ID: oval:org.mitre.oval:def:21429
Title: RHSA-2012:1122: bind97 security update (Important)
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: patch
Reference(s): RHSA-2012:1122-00
CESA-2012:1122
CVE-2012-3817
Version: 4
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Product(s): bind97
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21496
 
Oval ID: oval:org.mitre.oval:def:21496
Title: RHSA-2012:1123: bind security update (Important)
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: patch
Reference(s): RHSA-2012:1123-01
CESA-2012:1123
CVE-2012-3817
Version: 4
Platform(s): Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
CentOS Linux 5
CentOS Linux 6
Product(s): bind
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23076
 
Oval ID: oval:org.mitre.oval:def:23076
Title: ELSA-2012:1122: bind97 security update (Important)
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: patch
Reference(s): ELSA-2012:1122-00
CVE-2012-3817
Version: 6
Platform(s): Oracle Linux 5
Product(s): bind97
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23358
 
Oval ID: oval:org.mitre.oval:def:23358
Title: DEPRECATED: ELSA-2012:1123: bind security update (Important)
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: patch
Reference(s): ELSA-2012:1123-01
CVE-2012-3817
Version: 7
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): bind
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23609
 
Oval ID: oval:org.mitre.oval:def:23609
Title: ELSA-2012:1123: bind security update (Important)
Description: ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.
Family: unix Class: patch
Reference(s): ELSA-2012:1123-01
CVE-2012-3817
Version: 6
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): bind
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27186
 
Oval ID: oval:org.mitre.oval:def:27186
Title: DEPRECATED: ELSA-2012-1123 -- bind security update (important)
Description: [32:9.8.2-0.10.rc1.2] - fix CVE-2012-3817
Family: unix Class: patch
Reference(s): ELSA-2012-1123
CVE-2012-3817
Version: 4
Platform(s): Oracle Linux 5
Oracle Linux 6
Product(s): bind
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 94

OpenVAS Exploits

Date Description
2012-11-16 Name : VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
File : nvt/gb_VMSA-2012-0016.nasl
2012-09-26 Name : Gentoo Security Advisory GLSA 201209-04 (bind)
File : nvt/glsa_201209_04.nasl
2012-08-30 Name : Fedora Update for bind FEDORA-2012-11146
File : nvt/gb_fedora_2012_11146_bind_fc17.nasl
2012-08-14 Name : Fedora Update for bind FEDORA-2012-11153
File : nvt/gb_fedora_2012_11153_bind_fc16.nasl
2012-08-10 Name : Debian Security Advisory DSA 2517-1 (bind9)
File : nvt/deb_2517_1.nasl
2012-08-10 Name : FreeBSD Ports: FreeBSD
File : nvt/freebsd_FreeBSD15.nasl
2012-08-10 Name : FreeBSD Ports: bind99
File : nvt/freebsd_bind99.nasl
2012-08-03 Name : CentOS Update for bind97 CESA-2012:1122 centos5
File : nvt/gb_CESA-2012_1122_bind97_centos5.nasl
2012-08-03 Name : CentOS Update for bind CESA-2012:1123 centos5
File : nvt/gb_CESA-2012_1123_bind_centos5.nasl
2012-08-03 Name : CentOS Update for bind CESA-2012:1123 centos6
File : nvt/gb_CESA-2012_1123_bind_centos6.nasl
2012-08-03 Name : RedHat Update for bind RHSA-2012:1123-01
File : nvt/gb_RHSA-2012_1123-01_bind.nasl
2012-07-30 Name : Mandriva Update for bind MDVSA-2012:119 (bind)
File : nvt/gb_mandriva_MDVSA_2012_119.nasl
2012-07-30 Name : Ubuntu Update for bind9 USN-1518-1
File : nvt/gb_ubuntu_USN_1518_1.nasl

Information Assurance Vulnerability Management (IAVM)

Date Description
2013-09-19 IAVM : 2013-A-0179 - Apple Mac OS X Security Update 2013-004
Severity : Category I - VMSKEY : V0040373
2012-11-29 IAVM : 2012-A-0189 - Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1
Severity : Category I - VMSKEY : V0035032

Snort® IPS/IDS

Date Description
2014-11-16 VMWare vSphere API SOAP request RetrieveProperties remote denial of service a...
RuleID : 31297 - Revision : 3 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

Date Description
2017-04-21 Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0066.nasl - Type : ACT_GATHER_INFO
2016-06-22 Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2016-0055.nasl - Type : ACT_GATHER_INFO
2016-02-29 Name : The remote VMware ESX / ESXi host is missing a security-related patch.
File : vmware_VMSA-2012-0016_remote.nasl - Type : ACT_GATHER_INFO
2015-01-19 Name : The remote Solaris system is missing a security patch for third-party software.
File : solaris11_bind_20130410.nasl - Type : ACT_GATHER_INFO
2014-11-08 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2012-1200.nasl - Type : ACT_GATHER_INFO
2014-11-08 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-1185.nasl - Type : ACT_GATHER_INFO
2014-10-10 Name : The remote device is missing a vendor-supplied security patch.
File : f5_bigip_SOL14316.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-296.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2012-494.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2012-493.nasl - Type : ACT_GATHER_INFO
2013-09-13 Name : The remote host is missing a Mac OS X update that fixes several security issues.
File : macosx_SecUpd2013-004.nasl - Type : ACT_GATHER_INFO
2013-09-13 Name : The remote host is missing a Mac OS X update that fixes several security issues.
File : macosx_10_8_5.nasl - Type : ACT_GATHER_INFO
2013-09-04 Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2012-113.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2012-1122.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2012-1123.nasl - Type : ACT_GATHER_INFO
2013-06-29 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2012-1122.nasl - Type : ACT_GATHER_INFO
2013-06-29 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2012-1123.nasl - Type : ACT_GATHER_INFO
2013-05-20 Name : The remote device is missing a vendor-supplied security patch.
File : juniper_psn-2013-04-918.nasl - Type : ACT_GATHER_INFO
2013-01-25 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_bind-120730.nasl - Type : ACT_GATHER_INFO
2012-12-07 Name : The remote Slackware host is missing a security update.
File : Slackware_SSA_2012-341-01.nasl - Type : ACT_GATHER_INFO
2012-11-16 Name : The remote VMware ESXi / ESX host is missing one or more security-related pat...
File : vmware_VMSA-2012-0016.nasl - Type : ACT_GATHER_INFO
2012-09-24 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201209-04.nasl - Type : ACT_GATHER_INFO
2012-09-06 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2012-119.nasl - Type : ACT_GATHER_INFO
2012-08-30 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_bind-8237.nasl - Type : ACT_GATHER_INFO
2012-08-10 Name : The remote Fedora host is missing a security update.
File : fedora_2012-11153.nasl - Type : ACT_GATHER_INFO
2012-08-10 Name : The remote Fedora host is missing a security update.
File : fedora_2012-11146.nasl - Type : ACT_GATHER_INFO
2012-08-07 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_0f020b7be03311e190a2000c299b62e1.nasl - Type : ACT_GATHER_INFO
2012-07-31 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2517.nasl - Type : ACT_GATHER_INFO
2012-07-31 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-1123.nasl - Type : ACT_GATHER_INFO
2012-07-31 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2012-1122.nasl - Type : ACT_GATHER_INFO
2012-07-27 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-1518-1.nasl - Type : ACT_GATHER_INFO
2012-07-25 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_0bc67930d5c311e1bef60024e81297ae.nasl - Type : ACT_GATHER_INFO
2012-07-25 Name : The remote name server may be affected by multiple denial of service vulnerab...
File : bind9_991_p2.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
APPLE http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
CONFIRM http://support.apple.com/kb/HT5880
https://kb.isc.org/article/AA-00729
DEBIAN http://www.debian.org/security/2012/dsa-2517
REDHAT http://rhn.redhat.com/errata/RHSA-2012-1122.html
http://rhn.redhat.com/errata/RHSA-2012-1123.html
SECTRACK http://www.securitytracker.com/id?1027296
SECUNIA http://secunia.com/advisories/51096
SLACKWARE http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&...
SUSE http://lists.opensuse.org/opensuse-updates/2012-08/msg00013.html
http://lists.opensuse.org/opensuse-updates/2012-08/msg00015.html
UBUNTU http://www.ubuntu.com/usn/USN-1518-1

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
Date Informations
2024-02-02 01:20:10
  • Multiple Updates
2024-02-01 12:05:56
  • Multiple Updates
2023-09-05 12:19:03
  • Multiple Updates
2023-09-05 01:05:49
  • Multiple Updates
2023-09-02 12:19:04
  • Multiple Updates
2023-09-02 01:05:55
  • Multiple Updates
2023-08-12 12:22:54
  • Multiple Updates
2023-08-12 01:05:55
  • Multiple Updates
2023-08-11 12:19:11
  • Multiple Updates
2023-08-11 01:06:05
  • Multiple Updates
2023-08-06 12:18:26
  • Multiple Updates
2023-08-06 01:05:56
  • Multiple Updates
2023-08-04 12:18:31
  • Multiple Updates
2023-08-04 01:05:58
  • Multiple Updates
2023-07-14 12:18:30
  • Multiple Updates
2023-07-14 01:05:53
  • Multiple Updates
2023-03-29 01:20:27
  • Multiple Updates
2023-03-28 12:06:01
  • Multiple Updates
2022-10-11 12:16:31
  • Multiple Updates
2022-10-11 01:05:36
  • Multiple Updates
2021-05-04 12:21:22
  • Multiple Updates
2021-04-22 01:25:29
  • Multiple Updates
2020-05-23 00:34:22
  • Multiple Updates
2018-10-31 00:20:21
  • Multiple Updates
2017-04-22 13:25:52
  • Multiple Updates
2016-06-28 19:14:36
  • Multiple Updates
2016-06-23 13:29:27
  • Multiple Updates
2016-04-26 22:08:37
  • Multiple Updates
2016-03-01 13:26:32
  • Multiple Updates
2015-01-21 13:25:41
  • Multiple Updates
2014-11-08 13:30:16
  • Multiple Updates
2014-10-11 13:26:14
  • Multiple Updates
2014-06-14 13:33:19
  • Multiple Updates
2014-02-17 11:12:29
  • Multiple Updates
2013-11-25 13:20:32
  • Multiple Updates
2013-11-11 12:40:01
  • Multiple Updates
2013-09-18 13:19:34
  • Multiple Updates
2013-05-10 22:43:51
  • Multiple Updates
2013-04-19 13:20:50
  • Multiple Updates
2013-03-26 13:18:37
  • Multiple Updates
2013-01-30 13:22:14
  • Multiple Updates