Description
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- Canonical / Ubuntu Linux20.04 – 20.04
- Debian / debian_linux10.0 – 10.0
- fedoraproject / fedora31 – 31
- fedoraproject / fedora32 – 32
- ISC / BIND9.11.14 – 9.11.19
- ISC / BIND9.11.14-s1 – 9.11.19-s1
- ISC / BIND99.11.14 through versions before 9.11.20 – 9.11.14 through versions before 9.11.20
- ISC / BIND99.16.0 through versions before 9.16.4 – 9.16.0 through versions before 9.16.4
- ISC / BIND99.11.14-S1 through versions before 9.11.20-S1 – 9.11.14-S1 through versions before 9.11.20-S1
- ISC / BIND99.14.9 through versions 9.14.12 – 9.14.9 through versions 9.14.12
- NetApp / steelstore_cloud_integrated_storage
- openSUSE / Leap15.2 – 15.2
- openSUSE / Leap15.1 – 15.1
References
- MISChttps://kb.isc.org/docs/cve-2020-8619
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/
- MISChttps://security.netapp.com/advisory/ntap-20200625-0003/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4399-1/
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4752
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
Updated 41m ago · 8 sources