RSA Authentication Manager 8.x Multiple Vulnerabilities in ISC BIND - False Positive
Originally Published: 2017-02-17
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
CVE Identifier(s)
Article Summary
The reported vulnerabilities discussed are:
- CVE-2016-9131
- CVE-2016-9147
- CVE-2016-9444
Link to Advisories
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9131
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9147
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9444
- https://kb.isc.org/article/AA-01439/74/CVE-2016-9131%3A-A-malformed-response-to-an-ANY-query-can-cause-an-assertion-failure-during-recursion.html
- https://kb.isc.org/article/AA-01440/74/CVE-2016-9147%3A-An-error-handling-a-query-response-containing-inconsistent-DNSSEC-information-could-cause-an-assertion-failure-.html
- https://kb.isc.org/article/AA-01441/74/CVE-2016-9444%3A-An-unusually-formed-DS-record-response-could-cause-an-assertion-failure.html
Alert Impact
Not Applicable
Alert Impact Explanation
-
CVE-2016-9131
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9147
Named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9444
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
Disclaimer
Related Articles
Access Manager - Multiple vulnerabilities reported in Spring Source "spring-core-3.0.3.RELEASE.jar" - False Positives 57Number of Views RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 60Number of Views OpenSSL Multiple Vulnerabilities in RSA products 618Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 91Number of Views Cisco ACS / ASA sends two requests to Authentication Manager 8.x 318Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?