Reachable Assertion in ISC BIND - CVE-2020-8617
Published: May 20, 2020 / Updated: June 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when checking validity of messages containing TSIG resource records within tsig.c. A remote attacker can send a specially crafted message and cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server.
Affected software
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for IBM System z (Structure A)
IBM AIX
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Junos OS
Slackware Linux
Opensuse
Fedora
Cloud Pak for Security (CP4S)
IBM VIOS
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind9 (Debian package)
bind9 (Ubuntu package)
bind (Alpine package)
bind (Red Hat package) main
dnsperf
bind
bind-chroot
bind-devel
bind-export-devel
bind-export-libs
bind-libs
bind-libs-lite
bind-lite-devel
bind-pkcs11
bind-pkcs11-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-utils
bind-license
python3-bind
bind-dyndb-ldap
Data Computing Appliance (DCA)
Red Hat OpenShift Container Platform
Juniper Junos Space
How to mitigate CVE-2020-8617
Cloud Pak for Security (CP4S) - update to 1.8.0.0
bind9 (Debian package) - addressed in versions 1:9.10.3.dfsg.P4-12.3+deb9u6, 1:9.11.5.P4+dfsg-5.1+deb10u1
bind9 (Ubuntu package) - addressed in versions 1:9.8.1.dfsg.P1-4ubuntu0.30, 1:9.9.5.dfsg-3ubuntu0.19+esm2, 1:9.10.3.dfsg.P4-8ubuntu1.16, 1:9.11.3+dfsg-1ubuntu1.12, 1:9.11.5.P4+dfsg-5.1ubuntu2.2, 1:9.16.1-0ubuntu2.1
bind (Alpine package) - update to 9.14.12-r0
bind (Red Hat package) main - addressed in versions 9.8.2-0.23.rc1.el6_5.9, 9.8.2-0.30.rc1.el6_6.11, 9.8.2-0.68.rc1.el6_10.7, 9.9.4-29.el7_2.9, 9.9.4-50.el7_3.4, 9.9.4-51.el7_4.4, 9.9.4-74.el7_6.4, 9.11.4-9.P2.el7_7.1, 9.11.4-16.P2.el7_8.6, 9.11.4-19.P2.el8_0, 9.11.4-26.P2.el8_1.3, 9.11.13-5.el8_2
Junos OS - addressed in versions 12.3X48-D95, 12.3X48-D105, 12.3R12-S15, 12.3R12-S19, 13.2X51-D40, 14.1X53-D30, 14.1X53-D53, 14.1X53-D140, 15.1x49-D190, 15.1X49-D200, 15.1X49-D230, 15.1X53-D593, 15.1R7-S6, 15.1R7-S9, 15.1R7-S10, 16.1R7-S6, 16.1R7-S7, 16.2R2-S11, 16.2R3, 17.1R2-S11, 17.1R3-S1, 17.1R3-S2, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S6, 17.3R3-S7, 17.3R3-S10, 17.3R3-S11, 17.3R3-S12, 17.4R2-S7, 17.4R2-S9, 17.4R2-S12, 17.4R2-S13, 17.4R3, 17.4R3-S3, 17.4R3-S4, 17.4R3-S5, 18.1R3-S8, 18.1R3-S9, 18.1R3-S11, 18.1R3-S12, 18.1R3-S13, 18.2R2-S6, 18.2R2-S7, 18.2R2-S8, 18.2R3-S1, 18.2R3-S3, 18.2R3-S6, 18.2R3-S7, 18.2R3-S8, 18.3R1-S5, 18.3R1-S7, 18.3R2-S2, 18.3R2-S3, 18.3R3, 18.3R3-S1, 18.3R3-S4, 18.3R3-S5, 18.4R1-S4, 18.4R1-S5, 18.4R1-S8, 18.4R2-S1, 18.4R2-S4, 18.4R2-S7, 18.4R2-S10, 18.4R3, 18.4R3-S6, 18.4R3-S8, 18.4R3-S10, 19.1R1-S3, 19.1R1-S4, 19.1R1-S6, 19.1R2, 19.1R2-S1, 19.1R3, 19.1R3-S3, 19.1R3-S4, 19.1R3-S5, 19.1R3-S7, 19.1R3-S9, 19.2R1-S1, 19.2R1-S3, 19.2R1-S6, 19.2R1-S7, 19.2R1-S8, 19.2R1-S9, 19.2R2, 19.2R3, 19.2R3-S1, 19.2R3-S2, 19.2R3-S4, 19.2R3-S5, 19.3R1, 19.3R1-S1, 19.3R2-S1, 19.3R2-S5, 19.3R2-S6, 19.3R3, 19.3R3-S1, 19.3R3-S2, 19.3R3-S4, 19.3R3-S5, 19.3R3-S6, 19.4R1, 19.4R1-S4, 19.4R2, 19.4R2-S2, 19.4R2-S4, 19.4R2-S6, 19.4R2-S7, 19.4R2-S8, 19.4R3, 19.4R3-S3, 19.4R3-S6, 19.4R3-S7, 19.4R3-S8, 19.4R3-S9, 19.4R3-S10, 20.1R1, 20.1R2, 20.1R2-S2, 20.1R3, 20.1R3-S3, 20.1R3-S4, 20.2R1-S2, 20.2R1-S3, 20.2R2, 20.2R2-S3, 20.2R3, 20.2R3-S3, 20.2R3-S4, 20.2R3-S5, 20.2R3-S6, 20.3R1, 20.3R2, 20.3R3-S2, 20.3R3-S3, 20.3R3-S4, 20.3R3-S5, 20.3R3-S6, 20.4R1-S1, 20.4R2, 20.4R3, 20.4R3-S1, 20.4R3-S3, 20.4R3-S4, 20.4R3-S5, 20.4R3-S8, 21.1R1, 21.1R2, 21.1R3-S1, 21.1R3-S3, 21.1R3-S4, 21.2R1, 21.2R2-S1, 21.2R2-S2, 21.2R3, 21.2R3-S1, 21.2R3-S2, 21.2R3-S4, 21.2R3-S6, 21.3R2, 21.3R3-S1, 21.3R3-S3, 21.3R3-S5, 21.4R1, 21.4R1-S1, 21.4R2, 21.4R2-S1, 21.4R3, 21.4R3-S1, 21.4R3-S4, 22.1R1, 22.1R1-S2, 22.1R2, 22.1R2-S2, 22.1R3, 22.1R3-S3, 22.2R1, 22.2R1-S1, 22.2R2, 22.2R2-S1, 22.2R3, 22.2R3-S1, 22.3R1, 22.3R1-S1, 22.3R2, 22.3R2-S2, 22.3R3, 22.4R1, 22.4R2-S1, 22.4R3, 23.2R1
dnsperf - update to 2.3.4-1.fc31
Data Computing Appliance (DCA) - update to 4.3.0.0
Red Hat OpenShift Container Platform - update to 4.3.25
bind - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind - addressed in versions 9.11.19-1.fc31, 9.11.19-1.fc32
python3-bind - update to 9.11.36-3
bind-dyndb-ldap - update to 11.2-3.fc31
Juniper Junos Space - update to 20.3R1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC Bind
- Slackware Linux update for bind
- Debian update for bind9
- Ubuntu update for Bind
- Ubuntu ESM update for Bind
- Arch Linux update for bind
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 8.1 Extended Update Support update for bind
- Red Hat Enterprise Linux 7 update for bind
- Red Hat Enterprise Linux 6 update for bind
- Amazon Linux AMI update for bind
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 7 update for bind
- Red Hat Enterprise Linux AUS 6.5 update for bind
- Red Hat Enterprise Linux AUS 6.6 update for bind
- Red Hat Enterprise Linux 7 update for bind
- Red Hat Enterprise Linux AUS 7.2 update for bind
- Red Hat Enterprise Linux Server AUS 7.3 update for bind
- IBM AIX update for BIND
- IBM VIOS update for BIND
- Reachable Assertion in bind (Alpine package)
- OpenSUSE Linux update for bind
- OpenSUSE Linux update for bind
- Juniper Junos OS update for bind
- Multiple vulnerabilities in Juniper Junos Space
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 7 update for bind
- Anolis OS update for bind (Anolis OS 8.6)
- Anolis OS update for bind
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.3
- Fedora 32 update for bind
- Fedora 31 update for bind, bind-dyndb-ldap, dnsperf