RSA Authentication Manager 8.x Multiple Vulnerabilities in ISC BIND - False Positive
Originally Published: 2017-02-17
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
CVE Identifier(s)
Article Summary
The reported vulnerabilities discussed are:
- CVE-2016-9131
- CVE-2016-9147
- CVE-2016-9444
Link to Advisories
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9131
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9147
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9444
- https://kb.isc.org/article/AA-01439/74/CVE-2016-9131%3A-A-malformed-response-to-an-ANY-query-can-cause-an-assertion-failure-during-recursion.html
- https://kb.isc.org/article/AA-01440/74/CVE-2016-9147%3A-An-error-handling-a-query-response-containing-inconsistent-DNSSEC-information-could-cause-an-assertion-failure-.html
- https://kb.isc.org/article/AA-01441/74/CVE-2016-9444%3A-An-unusually-formed-DS-record-response-could-cause-an-assertion-failure.html
Alert Impact
Not Applicable
Alert Impact Explanation
-
CVE-2016-9131
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9147
Named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9444
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
Disclaimer
Related Articles
RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 60Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 88Number of Views OpenSSL Multiple Vulnerabilities in RSA products 612Number of Views Access Manager - Multiple vulnerabilities reported in Spring Source "spring-core-3.0.3.RELEASE.jar" - False Positives 56Number of Views Deployment Considerations for Risk-Based Authentication 14Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?