PT-2020-6021 · Isc+4 · Bind+4

Joseph Gullo

·

Published

2020-08-20

·

Updated

2024-06-15

·

CVE-2020-8621

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.14.0 through 9.16.5 BIND versions 9.17.0 through 9.17.3
Description The issue arises when a server is configured with both QNAME minimization and 'forward first'. An attacker who can send queries to the server may be able to trigger a condition that causes the server to crash. This does not affect servers that 'forward only'. The vulnerability is due to insufficient input validation, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For BIND versions 9.14.0 through 9.16.5, consider disabling QNAME minimization when 'forward first' is configured to prevent the server from crashing. For BIND versions 9.17.0 through 9.17.3, consider disabling QNAME minimization when 'forward first' is configured to prevent the server from crashing. As a temporary workaround, consider restricting the 'forward first' configuration to minimize the risk of exploitation.

Exploit

Fix

Assertion Failure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02673
CVE-2020-8621
OPENSUSE-SU-2020:1699-1
OPENSUSE-SU-2020:1701-1
OPENSUSE-SU-2020_1699-1
OPENSUSE-SU-2020_1701-1
OPENSUSE-SU-2024:10650-1
SUSE-SU-2020:2914-1
USN-4468-1

Affected Products

Bind
Bind Server
Linuxmint
Suse
Ubuntu