QID 330085

Date Published: 2021-08-06

QID 330085: IBM AIX BIND Denial of Service Vulnerability (bind_advisory19)

CVE-2021-25215: By sending a query for DNAME records, an attacker could exploit this vulnerability to trigger a failed assertion check and terminate the named process.

Affected Versions:
AIX 7.1, 7.2

QID Detection logic:
This QID checks for the vulnerable versions of AIX.

By sending a query for DNAME records, an attacker could exploit this vulnerability to trigger a failed assertion check and terminate the named process causing denial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability. Refer to AIX bind to obtain more information.

    CVEs related to QID 330085

    Software Advisories
    Advisory ID Software Component Link
    bind_advisory19 URL Logo aix.software.ibm.com/aix/efixes/security/bind_advisory19.asc