Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.144437
Kategorie:Denial of Service
Titel:ISC BIND DoS Vulnerability (CVE-2020-8621) - Linux
Zusammenfassung:ISC BIND is prone to a denial of service vulnerability.
Beschreibung:Summary:
ISC BIND is prone to a denial of service vulnerability.

Vulnerability Insight:
While query forwarding and QNAME minimization are mutually incompatible, BIND
did sometimes allow QNAME minimization when continuing with recursion after 'forward first' did not result in an
answer. In these cases the data used by QNAME minimization might be inconsistent, leading to an assertion failure
causing the server to exit.

Vulnerability Impact:
If a server is configured with both QNAME minimization and 'forward first' then
an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash.

Servers that 'forward only' are not affected.

Affected Software/OS:
BIND 9.14.0 - 9.16.5 and 9.17.0 - 9.17.3.

Solution:
Update to version 9.16.6, 9.17.4 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-8621
https://kb.isc.org/docs/cve-2020-8621
https://security.gentoo.org/glsa/202008-19
SuSE Security Announcement: openSUSE-SU-2020:1699 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
SuSE Security Announcement: openSUSE-SU-2020:1701 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
https://usn.ubuntu.com/4468-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.