suse · CVE-2017-3140

Quick triage

Priority: medium Published: 2021-05-30 13:50:48 UTC Updated: 2026-04-18 15:47:51 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-3140 severity moderate: SUSE including 143 source package names (bind, bind-9.11.2-10.4, …), 506 product×package rows across 69 product lines (SLES for SAP Applications 11 SP2, SUSE CaaS Platform 4.0, … (69 product lines)): Known Not Affected 377, Fixed 129.

Description:

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

cvelogic Threat Intelligence