Back

MEDIUM

A truncated TSIG response can lead to an assertion failure

Published Aug 21, 2020

Description

In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND:

BIND 9.11.22 BIND 9.16.6 BIND 9.17.4

BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.

BIND 9.11.22-S1

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Aug 21, 2020
Updated Sep 16, 2024
Reserved Feb 5, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 20, 2020