Back

MEDIUM

A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer

Published Jun 17, 2020

Description

An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND:

BIND 9.16.4

Red Hat statement

This flaw only affects bind-9.16.x, therefore versions of BIND shipped with Red Hat Products are not affected by this flaw.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jun 17, 2020
Updated Sep 16, 2024
Reserved Feb 5, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 17, 2020
ENISA EUVD
Assigner isc
Published Jun 17, 2020
Updated Sep 16, 2024
Exploited since n/a
EUVD-2020-29466