Oval Definition:oval:com.ubuntu.xenial:def:201731380000000
Revision Date:2019-01-16Version:1
Title:CVE-2017-3138 on Ubuntu 16.04 LTS (xenial) - medium.
Description:named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-3138
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND bind9 package in xenial was vulnerable but has been fixed (note: '1:9.10.3.dfsg.P4-8ubuntu1.6').
  • BACK