CVE-2020-8619

Severity
4.9MEDIUM
EPSS
6.9%
top 8.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 24

Description

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition t

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages5 packages

Debianbind9< 1:9.16.4-1+3
Ubuntubind9< 1:9.16.1-0ubuntu2.2
CVEListV5isc/bind94 versions+3
NVDisc/bind9.11.149.11.19+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, Fedora 31, 32, Ubuntu Linux 20.04

🔴Vulnerability Details

4
GHSA
GHSA-fw3j-5rrr-7j3r: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an2022-05-24
CVEList
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer2020-06-17
OSV
CVE-2020-8619: In ISC BIND9 versions BIND 92020-06-17
OSV
bind9 vulnerabilities2020-06-17

📋Vendor Advisories

4
Red Hat
bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c2020-06-17
Ubuntu
Bind vulnerabilities2020-06-17
Microsoft
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer2020-06-09
Debian
CVE-2020-8619: bind9 - In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16...2020

💬Community

3
Bugzilla
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution2020-09-08
Bugzilla
CVE-2020-8619 bind: An asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c [fedora-all]2020-06-18
Bugzilla
CVE-2020-8619 bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c2020-06-16
CVE-2020-8619 (MEDIUM CVSS 4.9) | In ISC BIND9 versions BIND 9.11.14 | cvebase.io