ZeroHour

CVE-2021-25214

CVSS 3.1
6.5 medium
EPSS
6%p93
Published
()
Modified
Description

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.

Vendors
iscdebianfedoraprojectsiemensnetapp
Products
bind, debian linux, fedora, sinec infrastructure network services, active iq unified manager, cloud backup, aff a250 firmware, aff 500f firmware, h300s firmware, h500s firmware, h700s firmware, h300e firmware
Weakness
CWE-617
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news