Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.144438
Category:Denial of Service
Title:ISC BIND DoS Vulnerability (CVE-2020-8621) - Windows
Summary:ISC BIND is prone to a denial of service vulnerability.
Description:Summary:
ISC BIND is prone to a denial of service vulnerability.

Vulnerability Insight:
While query forwarding and QNAME minimization are mutually incompatible, BIND
did sometimes allow QNAME minimization when continuing with recursion after 'forward first' did not result in an
answer. In these cases the data used by QNAME minimization might be inconsistent, leading to an assertion failure
causing the server to exit.

Vulnerability Impact:
If a server is configured with both QNAME minimization and 'forward first' then
an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash.

Servers that 'forward only' are not affected.

Affected Software/OS:
BIND 9.14.0 - 9.16.5 and 9.17.0 - 9.17.3.

Solution:
Update to version 9.16.6, 9.17.4 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-8621
https://kb.isc.org/docs/cve-2020-8621
https://security.gentoo.org/glsa/202008-19
SuSE Security Announcement: openSUSE-SU-2020:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
SuSE Security Announcement: openSUSE-SU-2020:1701 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
https://usn.ubuntu.com/4468-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.