CVE Database
/

CVE-2020-8616

Back to search

CVE-2020-8616

Published: May 19, 2020

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

8.6

HIGH

Description

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.

VendorProductVersions

ISC

BIND9

affected
9.0.0 -> 9.11.18, 9.12.0 -> 9.12.4-P2, 9.14.0 -> 9.14.11, 9.16.0 -> 9.16.2, and releases 9.17.0 -> 9.17.1 of the 9.17 experimental development branch. All releases in the obsolete 9.13 and 9.15 development branches. All releases of BIND Supported Preview Edition from 9.9.3-S1 -> 9.11.18-S1

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

High

References

DSA-4689
vendor-advisory
x_refsource_DEBIAN
USN-4365-2
vendor-advisory
x_refsource_UBUNTU
USN-4365-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2020-2d89cbcfd9
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-f9dcd4e9d5
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2020:1699
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1701
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now