QID 15125
Date Published: 2021-05-10
QID 15125: ISC BIND Broken Inbound Incremental Zone Update Vulnerability
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
CVE-2021-25214: A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly
Affected software:
BIND 9.8.5 -> 9.8.8
BIND 9.9.3 -> 9.11.29
BIND 9.9.3-S1 -> 9.11.29-S1
BIND 9.16.8-S1 -> 9.16.13-S1
BIND 9.17.0 -> 9.17.11
Patched Versions:
BIND 9.11.22
BIND 9.16.6
BIND 9.17.4
BIND 9.11.22-S1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successfully exploitation could affects integrity, availability, confidentiality
Solution
Customers are advised to upgrade to the patched version 9.11.31, 9.16.15, 9.17.12, 9.11.31-S1, 9.16.15-S1 or latest release of ISC BIND.Workaround:
Disabling incremental zone transfers (IXFR) by setting request-ixfr no; in the desired configuration block (options, zone, or server) prevents the failing assertion from being evaluated.
Disabling incremental zone transfers (IXFR) by setting request-ixfr no; in the desired configuration block (options, zone, or server) prevents the failing assertion from being evaluated.
Vendor References
- BIND CVE-2021-25214 -
kb.isc.org/v1/docs/cve-2021-25214
CVEs related to QID 15125
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| BIND CVE-2021-25214 |
|