Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.146641
Category:Denial of Service
Title:ISC BIND DoS Vulnerability (CVE-2020-8619) - Windows
Summary:ISC BIND is prone to a denial of service (DoS) vulnerability.
Description:Summary:
ISC BIND is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
The asterisk character ('*') is allowed in DNS zone files,
where it is most commonly present as a wildcard at a terminal node of the Domain Name System
graph. However, the RFCs do not require and BIND does not enforce that an asterisk character be
present only at a terminal node.

A problem can occur when an asterisk is present in an empty non-terminal location within the DNS
graph. If such a node exists, after a series of queries, named can reach an inconsistent state
that results in the failure of an assertion check in rbtdb.c, followed by the program exiting due
to the assertion failure.

Vulnerability Impact:
Unless a nameserver is providing authoritative service for one
or more zones and at least one zone contains an empty non-terminal entry containing an asterisk
('*') character, this defect cannot be encountered. A would-be attacker who is allowed to change
zone content could theoretically introduce such a record in order to exploit this condition to
cause denial of service, though we consider the use of this vector unlikely because any such
attack would require a significant privilege level and be easily traceable.

Affected Software/OS:
BIND 9.11.14 through 9.11.19, 9.14.9 through 9.14.12, 9.16.0
through 9.16.3 and 9.11.14-S1 through 9.11.19-S1.

Solution:
Update to version 9.11.20, 9.16.4, 9.11.20-S1 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-8619
https://kb.isc.org/docs/cve-2020-8619
Debian Security Information: DSA-4752 (Google Search)
https://www.debian.org/security/2020/dsa-4752
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/
SuSE Security Announcement: openSUSE-SU-2020:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
SuSE Security Announcement: openSUSE-SU-2020:1701 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
https://usn.ubuntu.com/4399-1/
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.