In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 22, 2024 | Aug 21, 2020 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Aug 21, 2020 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Sep 8, 2020 | Aug 21, 2020 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Aug 31, 2020 | Aug 21, 2020 |
| Oracle Solaris | — | Upgrade service/network/dns/bind to version 9.11.22.0.0-11.4.26.0.1.75.1 on Solaris 11.4Upgrade network/dns/bind to version 9.11.22.0.0-11.4.26.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Aug 21, 2020 |
| Suse | — | Upgrade bind-devel-32bitUpgrade libisccfg1600-32bitUpgrade sysuser-toolsUpgrade python3-bindUpgrade libirs-develUpgrade libns1604-32bitUpgrade sysuser-shadowUpgrade bind-develUpgrade bind-chrootenvUpgrade bind-utilsUpgrade libisccc1600-32bitUpgrade libirs1601-32bitUpgrade libuv1-32bitUpgrade libdns1605-32bitUpgrade libuv1Upgrade libbind9-1600-32bitUpgrade bind-docUpgrade libbind9-1600Upgrade bindUpgrade libisccfg1600Upgrade libirs1601Upgrade libuv-develUpgrade libisc1606-32bitUpgrade libisc1606Upgrade libisccc1600Upgrade libdns1605Upgrade libns1604 | Oct 14, 2020 | Aug 21, 2020 |
| Ubuntu | — | Upgrade bind9 | Aug 22, 2020 | Aug 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub