CVE-2020-8619

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-8619.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-8619

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202006-13

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:9.16.4-1
debian debianbullseyefixed1:9.16.4-1
debian debianforkyfixed1:9.16.4-1
debian debiansidfixed1:9.16.4-1
debian debiantrixiefixed1:9.16.4-1
arch archfixed9.16.4-1
suse slesaffected

References

Verify integrity in audit chain (admin only). AS-IS.