Reachable Assertion in ISC BIND - CVE-2020-8619
Published: June 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when processing entries with an asterisk ("*") character in rbtdb.c. Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, an attacker with ability to change zone content can trigger assertion failure and perform a denial of service (DoS) attack.
Note, this vulnerability may affect hosting provider that allow users access to domain management functionality.
Affected software
Arch Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
pcre (Alpine package)
bind (Red Hat package) main
bind9 (Debian package)
bind (Alpine package)
bind
How to mitigate CVE-2020-8619
pcre (Alpine package) - update to 8.42-r2
bind (Red Hat package) main - update to 9.11.20-5.el8
bind9 (Debian package) - update to 9.11.5.P4+dfsg-5.1+deb10u2
bind (Alpine package) - update to 9.16.5-r0
bind - addressed in versions 9.11.20-1.fc31, 9.11.20-1.fc32
External References
Related Security Bulletins
- Denial of service in ISC Bind
- Slackware Linux update for bind
- Arch Linux update for bind
- Reachable Assertion in bind (Alpine package)
- Debian update for bind9
- OpenSUSE Linux update for bind
- OpenSUSE Linux update for bind
- Red Hat Enterprise Linux 8 update for bind
- Reachable Assertion in pcre (Alpine package)
- Fedora 32 update for bind
- Fedora 31 update for bind