Reachable Assertion in ISC BIND - CVE-2020-8619

 

Reachable Assertion in ISC BIND - CVE-2020-8619

Published: June 19, 2020


Vulnerability identifier: #VU29151
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8619
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion when processing entries with an asterisk ("*") character in rbtdb.c. Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, an attacker with ability to change zone content can trigger assertion failure and perform a denial of service (DoS) attack.

Note, this vulnerability may affect hosting provider that allow users access to domain management functionality.


Affected software

ISC BIND
Arch Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
pcre (Alpine package)
bind (Red Hat package) main
bind9 (Debian package)
bind (Alpine package)
bind

How to mitigate CVE-2020-8619

Install updates from vendor's website.

ISC BIND - addressed in versions 9.11.20, 9.11.20-S1, 9.16.4
pcre (Alpine package) - update to 8.42-r2
bind (Red Hat package) main - update to 9.11.20-5.el8
bind9 (Debian package) - update to 9.11.5.P4+dfsg-5.1+deb10u2
bind (Alpine package) - update to 9.16.5-r0
bind - addressed in versions 9.11.20-1.fc31, 9.11.20-1.fc32

External References

Related Security Bulletins