QID 330098

Date Published: 2022-03-14

QID 330098: IBM AIX BIND Denial of Service (DoS) Vulnerability (bind_advisory20)

CVE-2020-8622: ISC BIND is vulnerable to a denial of service, caused by a flaw in response processing, an attacker could exploit this vulnerability to cause a named resolver to spend most of its CPU time on managing and checking the lame cache and severely degrade resolver performance.

Affected Versions:
AIX 7.1, 7.2,7.3

QID Detection logic:
This QID checks for the vulnerable versions of AIX.

A successful exploit could lead to denial of service vulnerability.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability. Refer to AIX bind to obtain more information.

    CVEs related to QID 330098

    Software Advisories
    Advisory ID Software Component Link
    bind_advisory20 URL Logo aix.software.ibm.com/aix/efixes/security/bind_advisory20.asc