CVE-2020-8619

CVSS v3.1 4.9 (Medium)
49% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.31 % (70th)
0.31% Progress
Affected Products 6
Advisories 14

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

Weaknesses
CWE-404
Improper Resource Shutdown or Release
CVE Status
PUBLISHED
CNA
Internet Systems Consortium (ISC)
Published Date
2020-06-17 22:15:13
(4 years ago)
Updated Date
2023-11-07 03:26:38
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Isc Bind from 9.11.14 version and 9.11.19 and prior versions cpe:2.3:a:isc:bind >= 9.11.14 <= 9.11.19
  Isc Bind from 9.11.14-s1 version and 9.11.19-s1 and prior versions cpe:2.3:a:isc:bind::*:*:*:preview >= 9.11.14-s1 <= 9.11.19-s1
  Isc Bind from 9.14.9 version and 9.14.12 and prior versions cpe:2.3:a:isc:bind >= 9.14.9 <= 9.14.12
  Isc Bind from 9.16.0 version and 9.16.3 and prior versions cpe:2.3:a:isc:bind >= 9.16.0 <= 9.16.3

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 31 cpe:2.3:o:fedoraproject:fedora:31
  Fedoraproject Fedora 32 cpe:2.3:o:fedoraproject:fedora:32

Configuration #3

    CPE23 From Up To
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
  Opensuse Leap 15.2 cpe:2.3:o:opensuse:leap:15.2

Configuration #4

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #5

    CPE23 From Up To
  Canonical Ubuntu Linux 20.04 cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts

Configuration #6

    CPE23 From Up To
  Netapp Steelstore Cloud Integrated Storage cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...