Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8621

Опубликовано: 20 авг. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

Отчет

This flaw only affects bind >= 9.14.x. Therefore versions of bind package shipped with Red Hat Enterprise Linux are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bindNot affected
Red Hat Enterprise Linux 5bind97Not affected
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1869471bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c

EPSS

Процентиль: 89%
0.04224
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
nvd
больше 5 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
msrc
больше 5 лет назад

Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c

CVSS3: 7.5
debian
больше 5 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured ...

CVSS3: 7.5
github
больше 3 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

EPSS

Процентиль: 89%
0.04224
Низкий

7.5 High

CVSS3