vulnerability

Amazon Linux AMI 2: CVE-2020-8623: Security patch for bind (ALAS-2020-1564)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
2020-08-21
Added
2020-12-10
Modified
2024-11-26

Description

In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker

Solution(s)

amazon-linux-ami-2-upgrade-bindamazon-linux-ami-2-upgrade-bind-chrootamazon-linux-ami-2-upgrade-bind-debuginfoamazon-linux-ami-2-upgrade-bind-develamazon-linux-ami-2-upgrade-bind-export-develamazon-linux-ami-2-upgrade-bind-export-libsamazon-linux-ami-2-upgrade-bind-libsamazon-linux-ami-2-upgrade-bind-libs-liteamazon-linux-ami-2-upgrade-bind-licenseamazon-linux-ami-2-upgrade-bind-lite-develamazon-linux-ami-2-upgrade-bind-pkcs11amazon-linux-ami-2-upgrade-bind-pkcs11-develamazon-linux-ami-2-upgrade-bind-pkcs11-libsamazon-linux-ami-2-upgrade-bind-pkcs11-utilsamazon-linux-ami-2-upgrade-bind-sdbamazon-linux-ami-2-upgrade-bind-sdb-chrootamazon-linux-ami-2-upgrade-bind-utils
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.