CVE-2020-8619
Description
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-8619.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-8619
Vendor advisory: arch — https://security.archlinux.org/ASA-202006-13
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1:9.16.4-1 |
| debian | bullseye | fixed | 1:9.16.4-1 |
| debian | forky | fixed | 1:9.16.4-1 |
| debian | sid | fixed | 1:9.16.4-1 |
| debian | trixie | fixed | 1:9.16.4-1 |
| arch | fixed | 9.16.4-1 | |
| sles | affected | |
References
Verify integrity in audit chain (admin only). AS-IS.