Description
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- ISC / BIND99.0.0 – unspecified
- ISC / BIND9unspecified – 9.11.22
- ISC / BIND99.12.0 – unspecified
- ISC / BIND9unspecified – 9.16.6
- ISC / BIND99.17.0 – unspecified
- ISC / BIND9unspecified – 9.17.4
- ISC / BIND99.9.3-S1 – Supported Preview*
References
- MISChttps://kb.isc.org/docs/cve-2020-8622
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQN62GBMCIC5AY4KYADGXNKVY6AJKSJE/
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4468-1/
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4468-2/
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4752
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKAMJZXR66P6S5LEU4SN7USSNCWTXEXP/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2020/08/msg00053.html
- MISChttps://security.gentoo.org/glsa/202008-19
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuoct2021.html
- MISChttps://security.netapp.com/advisory/ntap-20200827-0003/
- MISChttps://www.synology.com/security/advisory/Synology_SA_20_19