Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8618

Опубликовано: 17 июн. 2020
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

An assertion check flaw caused by a buffer boundary check condition was found in BIND. A remote attacker could trigger this flaw via a large response, during zone transfer. The highest threat from this vulnerability is to system availability.

Отчет

This flaw only affects bind-9.16.x, therefore versions of BIND shipped with Red Hat Products are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bindNot affected
Red Hat Enterprise Linux 5bind97Not affected
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125->CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1847242bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer

EPSS

Процентиль: 79%
0.01297
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 5 лет назад

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

CVSS3: 4.9
nvd
больше 5 лет назад

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

CVSS3: 4.9
msrc
больше 5 лет назад

A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer

CVSS3: 4.9
debian
больше 5 лет назад

An attacker who is permitted to send zone data to a server via zone tr ...

CVSS3: 4.9
github
больше 3 лет назад

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

EPSS

Процентиль: 79%
0.01297
Низкий

4.9 Medium

CVSS3