Search 187964 CVE descriptions
and 85075 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Title:ISC BIND update-policy Enforcement Vulnerability - CVE-2020-8624 (Windows)
Summary:ISC BIND is prone to a vulnerability where update-policy rules of type; 'subdomain' are enforced incorrectly.
ISC BIND is prone to a vulnerability where update-policy rules of type
'subdomain' are enforced incorrectly.

Vulnerability Insight:
Change 4885 inadvertently caused 'update-policy' rules of type 'subdomain' to
be treated as if they were of type 'zonesub', allowing updates to all parts of the zone along with the intended

Vulnerability Impact:
An attacker who has been granted privileges to change a specific subset of the
zone's content could abuse these unintended additional privileges to update other contents of the zone.

Affected Software/OS:
BIND 9.9.12 - 9.9.13, 9.10.7 - 9.10.8, 9.11.3 - 9.11.21, 9.12.1 - 9.16.5,
9.17.0 - 9.17.3, also affects 9.9.12-S1 - 9.9.13-S1 and 9.11.3-S1 - 9.11.21-S1.

Update to version 9.11.22, 9.16.6, 9.17.4, 9.11.22-S1 or later.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-8624
Debian Security Information: DSA-4752 (Google Search)
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 85075 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2020 E-Soft Inc. All rights reserved.