Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-8621

Опубликовано: 21 авг. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 7.5

Описание

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

released

1:9.16.6-2ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

released

1:9.16.1-0ubuntu2.3
esm-infra/xenial

not-affected

code not present
focal

released

1:9.16.1-0ubuntu2.3
precise/esm

not-affected

code not present
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 86%
0.02968
Низкий

4.3 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 6 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
nvd
почти 6 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

CVSS3: 7.5
msrc
почти 6 лет назад

Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c

CVSS3: 7.5
debian
почти 6 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured ...

CVSS3: 7.5
github
около 4 лет назад

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

EPSS

Процентиль: 86%
0.02968
Низкий

4.3 Medium

CVSS2

7.5 High

CVSS3