A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
Published Jun 17, 2020
4.9
MEDIUMCVSS 3.1
EPSS 2.10%
Description
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
Affected products
-
- Version 9.11.14 through versions before 9.11.20StatusaffectedConstraints-
- Version 9.11.14-S1 through versions before 9.11.20-S1StatusaffectedConstraints-
- Version 9.14.9 through versions 9.14.12StatusaffectedConstraints-
- Version 9.16.0 through versions before 9.16.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 31
- 32
Configuration 4
- 10.0
Configuration 5
- 20.04
Configuration 6
- n/a
No data.
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8
Fixed · RHSA-2020:4500
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8
Fixed · RHSA-2020:4500
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 5
bind97
Not affected
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8 | Fixed | RHSA-2020:4500 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8 | Fixed | RHSA-2020:4500 |
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND:
BIND 9.11.20 BIND 9.16.4
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
BIND 9.11.20-S1
Red Hat statement
Based on upstream affected versions, this flaw only affects the versions of bind shipped with Red Hat Enterprise Linux 8.
Red Hat mitigation
As per upstream advisory: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8619 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1847244 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29467 Advisory
- https://kb.isc.org/docs/cve-2020-8619 x_refsource_CONFIRMVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-8619
- https://security.netapp.com/advisory/ntap-20200625-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4399-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8619
- https://www.debian.org/security/2020/dsa-4752 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.