Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.146640
Kategorie:Denial of Service
Titel:ISC BIND DoS Vulnerability (CVE-2020-8619) - Linux
Zusammenfassung:ISC BIND is prone to a denial of service (DoS) vulnerability.
Beschreibung:Summary:
ISC BIND is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
The asterisk character ('*') is allowed in DNS zone files,
where it is most commonly present as a wildcard at a terminal node of the Domain Name System
graph. However, the RFCs do not require and BIND does not enforce that an asterisk character be
present only at a terminal node.

A problem can occur when an asterisk is present in an empty non-terminal location within the DNS
graph. If such a node exists, after a series of queries, named can reach an inconsistent state
that results in the failure of an assertion check in rbtdb.c, followed by the program exiting due
to the assertion failure.

Vulnerability Impact:
Unless a nameserver is providing authoritative service for one
or more zones and at least one zone contains an empty non-terminal entry containing an asterisk
('*') character, this defect cannot be encountered. A would-be attacker who is allowed to change
zone content could theoretically introduce such a record in order to exploit this condition to
cause denial of service, though we consider the use of this vector unlikely because any such
attack would require a significant privilege level and be easily traceable.

Affected Software/OS:
BIND 9.11.14 through 9.11.19, 9.14.9 through 9.14.12, 9.16.0
through 9.16.3 and 9.11.14-S1 through 9.11.19-S1.

Solution:
Update to version 9.11.20, 9.16.4, 9.11.20-S1 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-8619
https://kb.isc.org/docs/cve-2020-8619
Debian Security Information: DSA-4752 (Google Search)
https://www.debian.org/security/2020/dsa-4752
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/
SuSE Security Announcement: openSUSE-SU-2020:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
SuSE Security Announcement: openSUSE-SU-2020:1701 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
https://usn.ubuntu.com/4399-1/
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.