PT-2021-2234 · Isc+8 · Bind+8

Published

2021-02-17

·

Updated

2024-06-15

·

CVE-2020-8625

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.5.0 through 9.11.27 BIND versions 9.12.0 through 9.16.11 BIND Supported Preview Edition versions 9.11.3-S1 through 9.11.27-S1 BIND Supported Preview Edition versions 9.16.8-S1 through 9.16.11-S1 BIND 9.17 development branch versions 9.17.0 through 9.17.1
Description The issue is related to a buffer overflow in the SPNEGO implementation used by BIND, which can be triggered when GSS-TSIG features are enabled. This can lead to a crash of the named process, and although unproven, remote code execution is theoretically possible. The vulnerability is more likely to be exposed in configurations where BIND is integrated with Samba or in mixed-server environments with Active Directory domain controllers. The tkey-gssapi-keytab and tkey-gssapi-credentialconfiguration options can render a server vulnerable if explicitly set.
Recommendations For BIND versions 9.5.0 through 9.11.27, update to version 9.11.28 or later. For BIND versions 9.12.0 through 9.16.11, update to version 9.16.12 or later. For BIND Supported Preview Edition versions 9.11.3-S1 through 9.11.27-S1, update to version 9.11.28-S1 or later. For BIND Supported Preview Edition versions 9.16.8-S1 through 9.16.11-S1, update to version 9.16.12-S1 or later. For BIND 9.17 development branch versions 9.17.0 through 9.17.1, update to version 9.17.10 or later. As a temporary workaround, consider disabling the GSS-TSIG features until a patch is available. Restrict access to the vulnerable tkey-gssapi-keytab and tkey-gssapi-credentialconfiguration options to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1370
ALT-PU-2021-1436
ALT-PU-2021-1836
BDU:2021-01179
CESA-2021_0670
CESA-2021_0671
CVE-2020-8625
DLA-2568-1
DSA-4857-1
MGASA-2021-0110
OESA-2021-1041
OPENSUSE-SU-2021:0375-1
OPENSUSE-SU-2021_0375-1
OPENSUSE-SU-2024:10650-1
RHSA-2021:0669
RHSA-2021:0670
RHSA-2021:0671
RHSA-2021:0672
RHSA-2021:0691
RHSA-2021:0692
RHSA-2021:0693
RHSA-2021:0694
RHSA-2021:0727
RHSA-2021:0922
RHSA-2021_0670
RHSA-2021_0671
RHSA-2021_0672
SUSE-SU-2021:0503-1
SUSE-SU-2021:0504-1
SUSE-SU-2021:0507-1
SUSE-SU-2021:14632-1
SUSE-SU-2021_0503-1
SUSE-SU-2021_0504-1
SUSE-SU-2021_0507-1
SUSE-SU-2021_14632-1
USN-4737-1
USN-4737-2
ZDI-21-195

Affected Products

Alt Linux
Astra Linux
Bind
Bind Server
Centos
Linuxmint
Red Hat
Suse
Ubuntu