#VU28123 Reachable Assertion in ISC BIND - CVE-2020-8617
Published: May 20, 2020 / Updated: June 3, 2020
ISC BIND
ISC
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when checking validity of messages containing TSIG resource records within tsig.c. A remote attacker can send a specially crafted message and cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server.