A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 22, 2024 | May 19, 2020 |
| Amazon Linux Ami 2 | — | Upgrade bindUpgrade bind-sdbUpgrade bind-export-develUpgrade bind-licenseUpgrade bind-export-libsUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-lite-develUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-libsUpgrade bind-sdb-chrootUpgrade bind-utilsUpgrade bind-libsUpgrade bind-libs-liteUpgrade bind-develUpgrade bind-pkcs11-develUpgrade bind-pkcs11 | May 22, 2020 | May 19, 2020 |
| Amazon_linux | — | Upgrade bind | Jun 4, 2020 | May 19, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 19, 2020 |
| Centos_linux | — | Upgrade bind-licenseUpgrade bind-utils-debuginfoUpgrade bind-export-libs-debuginfoUpgrade bind-pkcs11Upgrade bind-pkcs11-develUpgrade bind-sdb-chrootUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-libsUpgrade bind-sdb-debuginfoUpgrade bind-debugsourceUpgrade bind-pkcs11-utils-debuginfoUpgrade bindUpgrade bind-libs-debuginfoUpgrade bind-export-develUpgrade bind-libs-lite-debuginfoUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-develUpgrade bind-pkcs11-libsUpgrade bind-lite-develUpgrade bind-libs-liteUpgrade python3-bindUpgrade bind-pkcs11-utilsUpgrade bind-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-chrootUpgrade bind-export-libs | May 29, 2020 | May 19, 2020 |
| Debian | — | Upgrade bind9 | May 21, 2020 | May 19, 2020 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 26, 2020 | May 19, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | May 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bind-licenseUpgrade bind-utilsUpgrade bindUpgrade bind-libs-liteUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11Upgrade bind-chrootUpgrade bind-libs | Jun 17, 2020 | May 19, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bindUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-pkcs11Upgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bind-utils | Sep 28, 2020 | May 19, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bindUpgrade bind-libs-liteUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-libsUpgrade bind-pkcs11 | Sep 3, 2020 | May 19, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade bind-licenseUpgrade bind-export-libsUpgrade python3-bindUpgrade bind-export-develUpgrade bind-pkcs11-utilsUpgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bindUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-pkcs11Upgrade bind-libs | Jul 31, 2020 | May 19, 2020 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory17 | Aug 24, 2020 | May 19, 2020 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.11.19.0.0-11.4.22.0.1.69.4 on Solaris 11.4Upgrade service/network/dns/bind to version 9.11.19.0.0-11.4.22.0.1.69.4 on Solaris 11.4 | Jan 19, 2021 | May 19, 2020 |
| Oracle_linux | — | Upgrade bind-export-libsUpgrade bind-sdb-chrootUpgrade bind-export-develUpgrade bind-pkcs11Upgrade bind-sdbUpgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bindUpgrade bind-lite-develUpgrade bind-utilsUpgrade bind-pkcs11-utilsUpgrade bind-develUpgrade bind-libsUpgrade bind-chrootUpgrade bind-libs-liteUpgrade python3-bindUpgrade bind-pkcs11-libs | Jun 4, 2020 | May 19, 2020 |
| Redhat_linux | — | Upgrade bind-pkcs11-utils-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-debuginfoUpgrade bind-export-libsUpgrade bind-chrootUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-lite-develUpgrade bind-sdbUpgrade bind-licenseUpgrade bind-export-develUpgrade bind-utils-debuginfoUpgrade bindUpgrade bind-debugsourceUpgrade bind-pkcs11Upgrade bind-export-libs-debuginfoUpgrade bind-pkcs11-libsUpgrade bind-sdb-chrootUpgrade bind-pkcs11-debuginfoUpgrade bind-libsUpgrade bind-pkcs11-utilsUpgrade bind-utilsUpgrade bind-libs-liteNo solution existsUpgrade bind-pkcs11-develUpgrade bind-libs-debuginfoUpgrade python3-bindUpgrade bind-devel | May 29, 2020 | May 19, 2020 |
| Suse | — | Upgrade libns1604Upgrade sysuser-shadowUpgrade bind-docUpgrade libuv1Upgrade libisc166-32bitUpgrade libirs1601Upgrade libdns1605Upgrade libisccc160Upgrade sysuser-toolsUpgrade libns1604-32bitUpgrade libdns169Upgrade libirs160Upgrade libirs1601-32bitUpgrade bind-libs-32bitUpgrade libisccc1600Upgrade libisccfg1600Upgrade python-bindUpgrade libisc166Upgrade python3-bindUpgrade bind-utilsUpgrade libisc1606-32bitUpgrade libdns1605-32bitUpgrade bindUpgrade bind-devel-32bitUpgrade liblwres160Upgrade libuv-develUpgrade libisccc1600-32bitUpgrade libuv1-32bitUpgrade bind-develUpgrade libbind9-1600-32bitUpgrade libirs-develUpgrade libbind9-1600Upgrade libisccfg160Upgrade libbind9-160Upgrade bind-chrootenvUpgrade libisc1606Upgrade bind-libsUpgrade libisccfg1600-32bit | May 21, 2020 | May 19, 2020 |
| Ubuntu | — | Upgrade bind9 (Ubuntu Pro)Upgrade bind9 | May 20, 2020 | May 19, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 19, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub