An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 22, 2024 | Jun 17, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 17, 2020 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jun 17, 2020 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 19, 2020 | Jun 17, 2020 |
| Freebsd | — | Upgrade bind916 | Jun 19, 2020 | Jun 18, 2020 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.11.20.0.0-11.4.24.0.1.75.1 on Solaris 11.4Upgrade service/network/dns/bind to version 9.11.20.0.0-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Jun 17, 2020 |
| Suse | — | Upgrade python3-bindUpgrade libisc1606Upgrade libns1604Upgrade libirs1601-32bitUpgrade libdns1605-32bitUpgrade libbind9-1600-32bitUpgrade libns1604-32bitUpgrade libisc1606-32bitUpgrade libuv1-32bitUpgrade libirs1601Upgrade libdns1605Upgrade libbind9-1600Upgrade libirs-develUpgrade libisccfg1600Upgrade sysuser-toolsUpgrade bind-develUpgrade bindUpgrade libisccc1600-32bitUpgrade bind-chrootenvUpgrade libuv1Upgrade libisccc1600Upgrade libuv-develUpgrade bind-devel-32bitUpgrade bind-utilsUpgrade sysuser-shadowUpgrade libisccfg1600-32bitUpgrade bind-doc | Oct 14, 2020 | Jun 17, 2020 |
| Ubuntu | — | Upgrade bind9 | Jun 18, 2020 | Jun 17, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub