Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8621

Опубликовано: 21 авг. 2020
Источник: debian
EPSS Низкий

Описание

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bind9fixed1:9.16.6-1package
bind9not-affectedbusterpackage
bind9not-affectedstretchpackage

Примечания

  • https://kb.isc.org/docs/cve-2020-8621

  • https://gitlab.isc.org/isc-projects/bind9/commit/81514ff925dfc6e0c293745e0fc8320a8af95586 (v9_16_6)

EPSS

Процентиль: 86%
0.02968
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
redhat
почти 6 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
nvd
почти 6 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
msrc
почти 6 лет назад

Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c

CVSS3: 7.5
github
около 4 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

EPSS

Процентиль: 86%
0.02968
Низкий