ZeroHour

CVE-2020-8621

CVSS 3.1
7.5 high
EPSS
3%p86
Published
()
Modified
Description

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.

Vendors
iscopensusecanonicalsynologynetapp
Products
bind, leap, ubuntu linux, dns server, steelstore cloud integrated storage
Weakness
CWE-617
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.