Vulnerability   
Search   
    Search 187964 CVE descriptions
and 85075 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.144437
Category:Denial of Service
Title:ISC BIND DoS Vulnerability - CVE-2020-8621 (Linux)
Summary:ISC BIND is prone to a denial of service vulnerability.
Description:Summary:
ISC BIND is prone to a denial of service vulnerability.

Vulnerability Insight:
While query forwarding and QNAME minimization are mutually incompatible, BIND
did sometimes allow QNAME minimization when continuing with recursion after 'forward first' did not result in an
answer. In these cases the data used by QNAME minimization might be inconsistent, leading to an assertion failure
causing the server to exit.

Vulnerability Impact:
If a server is configured with both QNAME minimization and 'forward first' then
an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash.

Servers that 'forward only' are not affected.

Affected Software/OS:
BIND 9.14.0 - 9.16.5 and 9.17.0 - 9.17.3.

Solution:
Update to version 9.16.6, 9.17.4 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-8621
https://kb.isc.org/docs/cve-2020-8621
https://security.gentoo.org/glsa/202008-19
https://usn.ubuntu.com/4468-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 85075 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.