CVE-2020-8621
Summary
| CVE | CVE-2020-8621 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-21 21:15:00 UTC |
| Updated | 2022-04-28 18:27:00 UTC |
| Description | In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected. |
Risk And Classification
Problem Types: CWE-617
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 20.04 | All | All | All |
| Application | Isc | Bind | All | All | All | All |
| Application | Isc | Bind | All | All | All | All |
| Application | Netapp | Steelstore Cloud Integrated Storage | - | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.2 | All | All | All |
| Application | Synology | Dns Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2020:1699-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| USN-4468-1: Bind vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| BIND: Multiple vulnerabilities (GLSA 202008-19) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE-2020-8621: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c - Security Advisories | CONFIRM | kb.isc.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2020:1701-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| August 2020 ISC BIND Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Synology Inc. | CONFIRM | www.synology.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: ISC would like to thank Joseph Gullo for bringing this vulnerability to our attention.