Reachable Assertion in ISC BIND - CVE-2020-8618
Published: June 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in rdataset.c when processing large responses during zone transfers. A remote attacker with ability to send zone data to a server via zone transfer can exploit this to intentionally trigger memory corruption and assertion failure with a specially constructed zone, denying service to clients.
Affected software
Arch Linux
Opensuse
bind (Alpine package)
How to mitigate CVE-2020-8618
bind (Alpine package) - update to 9.16.5-r0