Reachable Assertion in ISC BIND - CVE-2020-8620

 

Reachable Assertion in ISC BIND - CVE-2020-8620

Published: August 20, 2020


Vulnerability identifier: #VU45821
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8620
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion in tcpdns.c when processing large TCP payloads. An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.


Affected software

ISC BIND
Gentoo Linux
Opensuse
Ubuntu
bind (Alpine package)
bind9 (Ubuntu package)

How to mitigate CVE-2020-8620

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.6, 9.17.4
bind (Alpine package) - update to 9.16.6-r0
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P4-8ubuntu1.17, 1:9.11.3+dfsg-1ubuntu1.13, 1:9.16.1-0ubuntu2.3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins