CVE-2020-8618
published 2020-06-17CVE-2020-8618: An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.85%
76.9th percentile
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.16.4-1 (bookworm) | bind9 1:9.16.4-1 (bookworm) |
| isc | bind | 9.16.0 – 9.16.3 | — |
| isc | bind9 | — | — |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.2 | 1:9.16.1-0ubuntu2.2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_bind_9.16.3-2_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_msrc4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2020-06-17·CVSS 4.9
CVE-2020-8618 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled large responses during zone
transfers. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. (CVE-2020-8618)
It was discovered that Bind incorrectly handled certain asterisk characters
in zone files. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2020-8619)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
vendor_redhat·2020-06-17·CVSS 4.9
CVE-2020-8618 [MEDIUM] CWE-617 bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
An assertion check flaw caused by a buffer boundary check condition was found in BIND. A remote attacker could trigger this flaw via a large response, during zone transfer. The highest threat from this vulnerability is to system availability.
Statement: This flaw only affects bind-9.16.x, therefore versions of BIND shipped with Red Hat Products are not affected by this flaw.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Microsoft
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
vendor_msrc·2020-06-09·CVSS 4.9
CVE-2020-8618 [MEDIUM] CWE-617 A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-Mariner Rele
Debian
CVE-2020-8618: bind9 - An attacker who is permitted to send zone data to a server via zone transfer can...
vendor_debian·2020·CVSS 4.9
CVE-2020-8618 [MEDIUM] CVE-2020-8618: bind9 - An attacker who is permitted to send zone data to a server via zone transfer can...
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
Scope: local
bookworm: resolved (fixed in 1:9.16.4-1)
bullseye: resolved (fixed in 1:9.16.4-1)
forky: resolved (fixed in 1:9.16.4-1)
sid: resolved (fixed in 1:9.16.4-1)
trixie: resolved (fixed in 1:9.16.4-1)
GHSA
GHSA-2c3j-p34f-v2cr: An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a sp
ghsa_unreviewed·2022-05-24
CVE-2020-8618 [MEDIUM] CWE-617 GHSA-2c3j-p34f-v2cr: An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a sp
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
OSV
CVE-2020-8618: An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a sp
osv·2020-06-17·CVSS 4.9
CVE-2020-8618 [MEDIUM] CVE-2020-8618: An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a sp
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
OSV
bind9 vulnerabilities
osv·2020-06-17·CVSS 4.9
CVE-2020-8618 [MEDIUM] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that Bind incorrectly handled large responses during zone
transfers. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. (CVE-2020-8618)
It was discovered that Bind incorrectly handled certain asterisk characters
in zone files. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2020-8619)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8618https://security.netapp.com/advisory/ntap-20200625-0003/https://usn.ubuntu.com/4399-1/http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8618https://security.netapp.com/advisory/ntap-20200625-0003/https://usn.ubuntu.com/4399-1/
2020-06-17
Published