A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 22, 2024 | May 19, 2020 |
| Amazon Linux Ami 2 | — | Upgrade bind-sdbUpgrade bindUpgrade bind-export-libsUpgrade bind-licenseUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-lite-develUpgrade bind-export-develUpgrade bind-pkcs11-develUpgrade bind-develUpgrade bind-libsUpgrade bind-sdb-chrootUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11Upgrade bind-libs-liteUpgrade bind-utils | May 22, 2020 | May 19, 2020 |
| Amazon_linux | — | Upgrade bind | Jun 4, 2020 | May 19, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 19, 2020 |
| Centos_linux | — | Upgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-libs-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-export-develUpgrade bind-export-libs-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-sdb-chrootUpgrade bind-licenseUpgrade bindUpgrade bind-pkcs11Upgrade bind-pkcs11-develUpgrade bind-libsUpgrade bind-debugsourceUpgrade bind-pkcs11-debuginfoUpgrade bind-export-libsUpgrade bind-pkcs11-libsUpgrade bind-lite-develUpgrade bind-libs-liteUpgrade bind-develUpgrade bind-sdbUpgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bind-debuginfoUpgrade python3-bindUpgrade bind-utilsUpgrade bind-libs-lite-debuginfo | May 29, 2020 | May 19, 2020 |
| Debian | — | Upgrade bind9 | May 21, 2020 | May 19, 2020 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 26, 2020 | May 19, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | May 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bind-licenseUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bind-libsUpgrade bindUpgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11Upgrade bind-utils | Jun 17, 2020 | May 19, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bind-pkcs11Upgrade bindUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-libs-liteUpgrade bind-pkcs11-libsUpgrade bind-chrootUpgrade bind-utils | Sep 28, 2020 | May 19, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bindUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11Upgrade bind-libs | Sep 3, 2020 | May 19, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade bind-licenseUpgrade python3-bindUpgrade bind-export-libsUpgrade bind-export-develUpgrade bind-pkcs11-utilsUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-libsUpgrade bindUpgrade bind-pkcs11 | Jul 31, 2020 | May 19, 2020 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory17 | Aug 24, 2020 | May 19, 2020 |
| Oracle Solaris | — | Upgrade service/network/dns/bind to version 9.11.19.0.0-11.4.22.0.1.69.4 on Solaris 11.4Upgrade network/dns/bind to version 9.11.19.0.0-11.4.22.0.1.69.4 on Solaris 11.4 | Jan 19, 2021 | May 19, 2020 |
| Oracle_linux | — | Upgrade python3-bindUpgrade bind-utilsUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-develUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bind-sdbUpgrade bind-export-libsUpgrade bind-pkcs11Upgrade bindUpgrade bind-export-develUpgrade bind-sdb-chroot | Jun 4, 2020 | May 19, 2020 |
| Redhat_linux | — | Upgrade bind-develUpgrade bind-sdb-chrootUpgrade bind-export-libs-debuginfoUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade bind-pkcs11Upgrade bind-libs-liteUpgrade bind-pkcs11-debuginfoUpgrade bind-libs-debuginfoUpgrade python3-bindNo solution existsUpgrade bind-libsUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-develUpgrade bind-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-sdbUpgrade bind-lite-develUpgrade bind-export-libsUpgrade bind-chrootUpgrade bindUpgrade bind-export-develUpgrade bind-licenseUpgrade bind-debugsourceUpgrade bind-pkcs11-libs-debuginfo | May 29, 2020 | May 19, 2020 |
| Suse | — | Upgrade libisccfg160Upgrade bind-devel-32bitUpgrade libirs-develUpgrade libbind9-160Upgrade libdns1605-32bitUpgrade libisccfg1600-32bitUpgrade bind-develUpgrade bindUpgrade bind-libsUpgrade libuv1-32bitUpgrade libuv-develUpgrade libbind9-1600Upgrade libisccc1600-32bitUpgrade libbind9-1600-32bitUpgrade bind-chrootenvUpgrade libisc1606Upgrade liblwres160Upgrade libdns1605Upgrade libns1604Upgrade sysuser-toolsUpgrade libisc166Upgrade python-bindUpgrade libirs1601Upgrade libisccc160Upgrade libirs160Upgrade libns1604-32bitUpgrade libisccc1600Upgrade libuv1Upgrade python3-bindUpgrade libisc1606-32bitUpgrade libisc166-32bitUpgrade sysuser-shadowUpgrade bind-libs-32bitUpgrade libirs1601-32bitUpgrade bind-utilsUpgrade bind-docUpgrade libisccfg1600Upgrade libdns169 | May 21, 2020 | May 19, 2020 |
| Ubuntu | — | Upgrade bind9Upgrade bind9 (Ubuntu Pro) | May 20, 2020 | May 19, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 19, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub