PT-2020-20240 · Isc+7 · Bind 9+7

Published

2020-06-17

·

Updated

2024-06-15

·

CVE-2020-8619

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ISC BIND9 versions 9.11.14 through 9.11.19 ISC BIND9 versions 9.14.9 through 9.14.12 ISC BIND9 versions 9.16.0 through 9.16.3 ISC BIND9 Supported Preview Edition versions 9.11.14-S1 through 9.11.19-S1
Description The issue arises when a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character. This could potentially be exploited by an attacker who can change zone content, introducing such a record to cause denial of service. However, this would require a significant privilege level and be easily traceable. The problem can also be triggered by remote attackers using a series of specially crafted queries when an asterisk is present in an empty non-terminal location within the DNS graph, leading to an assertion failure.
Recommendations For versions 9.11.14 through 9.11.19, update to a version outside of this range to resolve the issue. For versions 9.14.9 through 9.14.12, update to a version outside of this range to resolve the issue. For versions 9.16.0 through 9.16.3, update to a version outside of this range to resolve the issue. For ISC BIND9 Supported Preview Edition versions 9.11.14-S1 through 9.11.19-S1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to zones that may contain empty non-terminal entries with an asterisk character until a patch is available.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2301
ALT-PU-2020-2685
CESA-2020_4500
CVE-2020-8619
DSA-4752-1
OPENSUSE-SU-2020:1699-1
OPENSUSE-SU-2020:1701-1
OPENSUSE-SU-2020_1699-1
OPENSUSE-SU-2020_1701-1
OPENSUSE-SU-2024:10650-1
RHSA-2020:4500
RHSA-2020_4500
SUSE-SU-2020:2914-1
USN-4399-1

Affected Products

Alt Linux
Bind 9
Bind Server
Centos
Linuxmint
Red Hat
Suse
Ubuntu