RSA Authentication Manager 8.x Multiple Vulnerabilities in ISC BIND - False Positive
Originally Published: 2017-02-17
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
CVE Identifier(s)
Article Summary
The reported vulnerabilities discussed are:
- CVE-2016-9131
- CVE-2016-9147
- CVE-2016-9444
Link to Advisories
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9131
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9147
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9444
- https://kb.isc.org/article/AA-01439/74/CVE-2016-9131%3A-A-malformed-response-to-an-ANY-query-can-cause-an-assertion-failure-during-recursion.html
- https://kb.isc.org/article/AA-01440/74/CVE-2016-9147%3A-An-error-handling-a-query-response-containing-inconsistent-DNSSEC-information-could-cause-an-assertion-failure-.html
- https://kb.isc.org/article/AA-01441/74/CVE-2016-9444%3A-An-unusually-formed-DS-record-response-could-cause-an-assertion-failure.html
Alert Impact
Not Applicable
Alert Impact Explanation
-
CVE-2016-9131
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9147
Named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
-
CVE-2016-9444
Named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Response: The flaw does not exist. The ISC BIND named service is not used in the RSA Authentication Manager 8.2 appliance.
Disclaimer
Related Articles
RSA Authentication Manager 8.2 Multiple Vulnerabilities - False Positive 60Number of Views OpenSSL Multiple Vulnerabilities in RSA products 616Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 91Number of Views Access Manager - Multiple vulnerabilities reported in Spring Source "spring-core-3.0.3.RELEASE.jar" - False Positives 56Number of Views Multiple Apache Tomcat Vulnerabilities in RSA Authentication Manager - False Positive 126Number of Views
Trending Articles
RSA Announces the Release of RSA MFA Agent 2.5 for Microsoft Windows RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to generate a PASSCODE for manual entry on a Ericsson R380 WAP phone How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide
Don't see what you're looking for?