CVE-2020-8619
published 2020-06-17CVE-2020-8619: In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
2.09%
79.5th percentile
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.16.4-1 (bookworm) | bind9 1:9.16.4-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| isc | bind | 9.11.14 – 9.11.19 | — |
| isc | bind | 9.11.14-s1 – 9.11.19-s1 | — |
| isc | bind | 9.14.9 – 9.14.12 | — |
| isc | bind | 9.16.0 – 9.16.3 | — |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.4-1 | 1:9.16.4-1 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.2 | 1:9.16.1-0ubuntu2.2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_bind_9.16.3-2_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_msrc4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw3j-5rrr-7j3r: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an
ghsa_unreviewed·2022-05-24
CVE-2020-8619 [MEDIUM] CWE-404 GHSA-fw3j-5rrr-7j3r: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an
Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
OSV
CVE-2020-8619: In ISC BIND9 versions BIND 9
osv·2020-06-17·CVSS 4.9
CVE-2020-8619 [MEDIUM] CVE-2020-8619: In ISC BIND9 versions BIND 9
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
OSV
bind9 vulnerabilities
osv·2020-06-17·CVSS 4.9
CVE-2020-8618 [MEDIUM] bind9 vulnerabilities
bind9 vulnerabilities
It was discovered that Bind incorrectly handled large responses during zone
transfers. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. (CVE-2020-8618)
It was discovered that Bind incorrectly handled certain asterisk characters
in zone files. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2020-8619)
Red Hat
bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c
vendor_redhat·2020-06-17·CVSS 4.9
CVE-2020-8619 [MEDIUM] CWE-617 bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c
bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
A flaw was found in bind when an as
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2020-06-17·CVSS 4.9
CVE-2020-8618 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled large responses during zone
transfers. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. (CVE-2020-8618)
It was discovered that Bind incorrectly handled certain asterisk characters
in zone files. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. (CVE-2020-8619)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
vendor_msrc·2020-06-09·CVSS 4.9
CVE-2020-8619 [MEDIUM] CWE-404 A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-Mariner Rele
Debian
CVE-2020-8619: bind9 - In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16...
vendor_debian·2020·CVSS 4.9
CVE-2020-8619 [MEDIUM] CVE-2020-8619: bind9 - In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16...
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
Scope: local
bookworm: resolved (fixed in 1:9.16.4-1)
bullseye: resolved (fixed in 1:9.16.4-1)
forky: resolved (fixed in 1:9.16.4
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8619 [HIGH] CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8619
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2020-8619 bind: An asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c [fedora-all]
bugzilla·2020-06-18·CVSS 4.9
CVE-2020-8619 [MEDIUM] CVE-2020-8619 bind: An asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c [fedora-all]
CVE-2020-8619 bind: An asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2020-8618 bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
bugzilla·2020-06-16·CVSS 4.9
CVE-2020-8618 [MEDIUM] CVE-2020-8618 bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
CVE-2020-8618 bind: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
As per upstream advisory:
An assertion check in BIND (that is meant to prevent going beyond the end of a buffer when processing incoming data) can be incorrectly triggered by a large response during zone transfer.
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
This flaw only affects bind-9.16 branch, other versions are not affected.
Discussion:
Acknowledgments:
Name: ISC
---
Statement:
This flaw only affects bind-9.16.x, therefore versions of BIND shipped with Red Hat Products are not affected by this flaw.
---
Exte
Bugzilla
CVE-2020-8619 bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c
bugzilla·2020-06-16·CVSS 4.9
CVE-2020-8619 [MEDIUM] CVE-2020-8619 bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c
CVE-2020-8619 bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c
As per upstream advisory:
The asterisk character ("*") is allowed in DNS zone files, where it is most commonly present as a wildcard at a terminal node of the Domain Name System graph. However, the RFCs do not require and BIND does not enforce that an asterisk character be present only at a terminal node.
A problem can occur when an asterisk is present in an empty non-terminal location within the DNS graph. If such a node exists, after a series of queries, named can reach an inconsistent state that results in the failure of an assertion check in rbtdb.c, followed by the program exiting due to the assertion failure.
Discussion:
Acknowledgments:
Name: ISC
---
Mitigation:
As per
arXiv
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
arxiv_fulltext·2023-10-04
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
https://faculty.sites.uci.edu/zhouli/research/ Qifan Zhang ,
https://faculty.sites.uci.edu/zhouli/research/ Xuesong Bai ,
https://netsec.ccert.edu.cn/people/lx19 Xiang Li ,
https://netsec.ccert.edu.cn/people/duanhx/ Haixin Duan ,
https://netsec.ccert.edu.cn/people/qli/ Qi Li , and
https://faculty.sites.uci.edu/zhouli/ Zhou Li
Corresponding authors. Most of Xiang Li's work was done when visiting UCI as a project specialist.
https://uci.edu/University of California, Irvine,
https://www.tsinghua.edu.cn/en/Tsinghua University
Zhongguancun Laboratory,
https://www.qcl.edu.cn/Quan Cheng Laboratory
## Abstract
Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8619https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/https://security.netapp.com/advisory/ntap-20200625-0003/https://usn.ubuntu.com/4399-1/https://www.debian.org/security/2020/dsa-4752http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8619https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/https://security.netapp.com/advisory/ntap-20200625-0003/https://usn.ubuntu.com/4399-1/https://www.debian.org/security/2020/dsa-4752
2020-06-17
Published