CVE Database
/

CVE-2020-8619

Back to search

CVE-2020-8619

Published: Jun 17, 2020

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.1

4.9

MEDIUM

Description

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

VendorProductVersions

ISC

BIND9

affected
9.11.14 through versions before 9.11.20
affected
9.16.0 through versions before 9.16.4
affected
9.11.14-S1 through versions before 9.11.20-S1
affected
9.14.9 through versions 9.14.12

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

FEDORA-2020-54a91444ff
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-5f8da4b260
vendor-advisory
x_refsource_FEDORA
USN-4399-1
vendor-advisory
x_refsource_UBUNTU
DSA-4752
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2020:1699
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1701
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now