In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 22, 2024 | Aug 21, 2020 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Aug 21, 2020 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Sep 8, 2020 | Aug 21, 2020 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Aug 31, 2020 | Aug 21, 2020 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.11.22.0.0-11.4.26.0.1.75.1 on Solaris 11.4Upgrade service/network/dns/bind to version 9.11.22.0.0-11.4.26.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Aug 21, 2020 |
| Suse | — | Upgrade libirs1601-32bitUpgrade python3-bindUpgrade libisc1606Upgrade libuv1-32bitUpgrade libbind9-1600-32bitUpgrade bind-docUpgrade libisc1606-32bitUpgrade libuv-develUpgrade libns1604Upgrade libirs1601Upgrade libuv1Upgrade libbind9-1600Upgrade libdns1605-32bitUpgrade bind-utilsUpgrade libisccc1600-32bitUpgrade bindUpgrade bind-chrootenvUpgrade sysuser-toolsUpgrade sysuser-shadowUpgrade libns1604-32bitUpgrade libisccc1600Upgrade libdns1605Upgrade bind-develUpgrade libirs-develUpgrade libisccfg1600-32bitUpgrade libisccfg1600Upgrade bind-devel-32bit | Oct 14, 2020 | Aug 21, 2020 |
| Ubuntu | — | Upgrade bind9 | Aug 22, 2020 | Aug 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub