Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8618

Опубликовано: 17 июн. 2020
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Версия от 9.16.0 (включая) до 9.16.3 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

EPSS

Процентиль: 79%
0.01297
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 5 лет назад

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

CVSS3: 4.9
redhat
больше 5 лет назад

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

CVSS3: 4.9
msrc
больше 5 лет назад

A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer

CVSS3: 4.9
debian
больше 5 лет назад

An attacker who is permitted to send zone data to a server via zone tr ...

CVSS3: 4.9
github
больше 3 лет назад

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

EPSS

Процентиль: 79%
0.01297
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-617