CVE-2023-3341

Name
CVE-2023-3341
Description
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary. This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://kb.isc.org/docs/cve-2023-3341
MISC http://www.openwall.com/lists/oss-security/2023/09/20/2
MISC https://www.debian.org/security/2023/dsa-5504
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPJLLTJCSDJJII7IIZPLTBQNWP7MZH7F/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U35OARLQCPMVCBBPHWBXY5M6XJLD2TZ5/
MISC https://security.netapp.com/advisory/ntap-20231013-0003/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSK5V4W4OHPM3JTJGWAQD6CZW7SFD75B/
security-officer@isc.org https://lists.debian.org/debian-lts-announce/2024/01/msg00021.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:* bind == None == 9.11.7
cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:* bind == None == 9.11.3
cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:* bind == None == 9.11.6
cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:* bind == None == 9.10.5
cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:* bind == None == 9.11.5
cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:* bind == None == 9.9.3
cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:* bind == None == 9.10.7
cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:* bind == None == 9.11.12
cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:* bind == None == 9.11.8
cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:* bind == None == 9.9.12
cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:* bind == None == 9.9.13
cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:* bind == None == 9.11.21
cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:* bind == None == 9.16.8
cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:* bind == None == 9.16.11
cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:* bind == None == 9.11.27
cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:* bind == None == 9.16.13
cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:* bind == None == 9.11.29
cpe:2.3:a:isc:bind:9.16.21:s1:*:*:supported_preview:*:*:* bind == None == 9.16.21
cpe:2.3:a:isc:bind:9.11.35:s1:*:*:supported_preview:*:*:* bind == None == 9.11.35
cpe:2.3:a:isc:bind:9.11.37:s1:*:*:supported_preview:*:*:* bind == None == 9.11.37
cpe:2.3:a:isc:bind:9.16.32:s1:*:*:supported_preview:*:*:* bind == None == 9.16.32
cpe:2.3:a:isc:bind:9.16.14:s1:*:*:supported_preview:*:*:* bind == None == 9.16.14
cpe:2.3:a:isc:bind:9.16.36:s1:*:*:supported_preview:*:*:* bind == None == 9.16.36
cpe:2.3:a:isc:bind:9.11.4:s1:*:*:supported_preview:*:*:* bind == None == 9.11.4
cpe:2.3:a:isc:bind:9.16.12:s1:*:*:supported_preview:*:*:* bind == None == 9.16.12
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* bind >= 9.19.0 < 9.19.17
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* bind >= 9.18.0 < 9.18.19
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* bind >= 9.2.0 < 9.16.44
cpe:2.3:a:isc:bind:9.16.43:s1:*:*:supported_preview:*:*:* bind == None == 9.16.43
cpe:2.3:a:isc:bind:9.18.18:s1:*:*:supported_preview:*:*:* bind == None == 9.18.18
cpe:2.3:a:isc:bind:9.18.0:s1:*:*:supported_preview:*:*:* bind == None == 9.18.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
bind 3.15-main 9.16.44-r0 None fixed