A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
Published Aug 21, 2020
7.5
HIGHCVSS 3.1
EPSS 6.40%
Description
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker
Affected products
-
Affected
- ≥ 9.10.0, < unspecified
- ≥ 9.10.5-S1, < Supported Preview*
- ≥ 9.12.0, < unspecified
- ≥ 9.17.0, < unspecified
- ≥ unspecified, < 9.11.22
- ≥ unspecified, < 9.16.6
- ≥ unspecified, < 9.17.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
Configuration 1
Configuration 3
- 31
- 32
Configuration 5
- 9.0
- 10.0
Configuration 6
- 16.04
- 18.04
- 20.04
Configuration 7
- < 2.2.2-5027
Configuration 8
- n/a
No data.
Red Hat Enterprise Linux 7
bind-32:9.11.4-26.P2.el7_9.2
Fixed · RHSA-2020:5011
Red Hat Enterprise Linux 7.6 Extended Update Support
bind-32:9.9.4-74.el7_6.5
Fixed · RHSA-2020:4992
Red Hat Enterprise Linux 7.7 Extended Update Support
bind-32:9.11.4-9.P2.el7_7.3
Fixed · RHSA-2020:5203
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8
Fixed · RHSA-2020:4500
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8
Fixed · RHSA-2020:4500
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 5
bind97
Not affected
Red Hat Enterprise Linux 6
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | bind-32:9.11.4-26.P2.el7_9.2 | Fixed | RHSA-2020:5011 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | bind-32:9.9.4-74.el7_6.5 | Fixed | RHSA-2020:4992 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | bind-32:9.11.4-9.P2.el7_7.3 | Fixed | RHSA-2020:5203 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8 | Fixed | RHSA-2020:4500 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8 | Fixed | RHSA-2020:4500 |
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND:
BIND 9.11.22 BIND 9.16.6 BIND 9.17.4
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
BIND 9.11.22-S1
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8623 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1869477 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29471 Advisory
- https://kb.isc.org/docs/cve-2020-8623 x_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00053.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQN62GBMCIC5AY4KYADGXNKVY6AJKSJE/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKAMJZXR66P6S5LEU4SN7USSNCWTXEXP/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-8623
- https://security.gentoo.org/glsa/202008-19 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200827-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4468-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8623
- https://www.debian.org/security/2020/dsa-4752 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_19 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data