CVE-2020-8620
published 2020-08-21CVE-2020-8620: In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.66%
88.4th percentile
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.16.6-1 (bookworm) | bind9 1:9.16.6-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | 9.15.6 – 9.16.5 | — |
| isc | bind | 9.17.0 – 9.17.3 | — |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.17 | 1:9.10.3.dfsg.P4-8ubuntu1.17 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.13 | 1:9.11.3+dfsg-1ubuntu1.13 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.3 | 1:9.16.1-0ubuntu2.3 |
| isc | bind9 | >= 9.15.6 < * | * |
| msrc | cm1_bind_9.16.3-2_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5fp-cw6q-m6xc: In BIND 9
ghsa_unreviewed·2022-05-24
CVE-2020-8620 [MEDIUM] CWE-617 GHSA-p5fp-cw6q-m6xc: In BIND 9
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
OSV
bind9 vulnerabilities
osv·2020-08-21·CVSS 7.5
CVE-2020-8620 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Emanuel Almeida discovered that Bind incorrectly handled certain TCP
payloads. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-8620)
Joseph Gullo discovered that Bind incorrectly handled QNAME minimization
when used in certain configurations. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-8621)
Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind
incorrectly handled certain truncated responses to a TSIG-signed request. A
remote attacker could possibly use this issue to cause Bind to crash,
resulting in a denial of service. (CVE-202
OSV
CVE-2020-8620: In BIND 9
osv·2020-08-21·CVSS 7.5
CVE-2020-8620 [HIGH] CVE-2020-8620: In BIND 9
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2020-08-21·CVSS 7.5
CVE-2020-8620 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Emanuel Almeida discovered that Bind incorrectly handled certain TCP
payloads. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-8620)
Joseph Gullo discovered that Bind incorrectly handled QNAME minimization
when used in certain configurations. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-8621)
Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind
incorrectly handled certain truncated responses to a TSIG-signed request. A
remote attacker could possibly use this issue to cau
Red Hat
bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
vendor_redhat·2020-08-20·CVSS 7.5
CVE-2020-8620 [HIGH] CWE-400 bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Statement: This version only affects bind-9.16.x. Therefore versions of bind package shipped with Red Hat Enterprise Linux are not affected by this flaw.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red Hat Enterprise Linux 8) - Not affected
Microsoft
In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the
vendor_msrc·2020-08-11·CVSS 7.5
CVE-2020-8620 [HIGH] CWE-617 In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the
In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the server to exit.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we
Debian
CVE-2020-8620: bind9 - In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP ...
vendor_debian·2020·CVSS 7.5
CVE-2020-8620 [HIGH] CVE-2020-8620: bind9 - In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP ...
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Scope: local
bookworm: resolved (fixed in 1:9.16.6-1)
bullseye: resolved (fixed in 1:9.16.6-1)
forky: resolved (fixed in 1:9.16.6-1)
sid: resolved (fixed in 1:9.16.6-1)
trixie: resolved (fixed in 1:9.16.6-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Google Chrome WebGL could lead to code execution
blogs_talos·2020-08-24·CVSS 7.5
[HIGH] Vulnerability Spotlight: Use-after-free vulnerability in Google Chrome WebGL could lead to code execution
## Vulnerability Spotlight: Use-after-free vulnerability in Google Chrome WebGL could lead to code execution
Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
The Google Chrome web browser contains a use-after-free vulnerability in its WebGL component that could allow a user to execute arbitrary code in the context of the browser process. This vulnerability
specifically exists in ANGLE, a compatibility layer between OpenGL and Direct3D that Chrome uses on Windows systems. An adversary could manipulate the memory layout of the browser in a way that they could gain control of the use-after-free exploit, which could ultimately lead to arbitrary code execution.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Google to ensure th
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Google Chrome WebGL could lead to code execution
blogs_talos·2020-08-24·CVSS 7.5
[HIGH] Vulnerability Spotlight: Use-after-free vulnerability in Google Chrome WebGL could lead to code execution
Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
The Google Chrome web browser contains a use-after-free vulnerability in its WebGL component that could allow a user to execute arbitrary code in the context of the browser process. This vulnerability
specifically exists in ANGLE, a compatibility layer between OpenGL and Direct3D that Chrome uses on Windows systems. An adversary could manipulate the memory layout of the browser in a way that they could gain control of the use-after-free exploit, which could ultimately lead to arbitrary code execution.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Google to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detail
Talos
Vulnerability Spotlight: Internet Systems Consortium BIND server DoS
blogs_talos·2020-08-20·CVSS 7.5
[HIGH] Vulnerability Spotlight: Internet Systems Consortium BIND server DoS
## Vulnerability Spotlight: Internet Systems Consortium BIND server DoS
Emanuel Almeida of Cisco Systems discovered this vulnerability. Blog by Jon Munshaw.
The Internet Systems Consortium’s BIND server contains a denial-of-service vulnerability that exists when processing TCP traffic through the libuv library. An attacker can exploit this vulnerability by flooding the TCP port and forcing the service to terminate.
The BIND nameserver is considered the reference implementation of the Domain Name System of the internet. It is capable of being an authoritative name server as well as a recursive cache for domain name queries on a network. This vulnerability only applies to this specific code and does not affect any other DNS software.
In accordance with our coordinated disclosure policy,
Talos
Vulnerability Spotlight: Internet Systems Consortium BIND server DoS
blogs_talos·2020-08-20·CVSS 7.5
[HIGH] Vulnerability Spotlight: Internet Systems Consortium BIND server DoS
Emanuel Almeida of Cisco Systems discovered this vulnerability. Blog by Jon Munshaw.
The Internet Systems Consortium’s BIND server contains a denial-of-service vulnerability that exists when processing TCP traffic through the libuv library. An attacker can exploit this vulnerability by flooding the TCP port and forcing the service to terminate.
The BIND nameserver is considered the reference implementation of the Domain Name System of the internet. It is capable of being an authoritative name server as well as a recursive cache for domain name queries on a network. This vulnerability only applies to this specific code and does not affect any other DNS software.
In accordance with our coordinated disclosure policy, Cisco Talos worked with ISC to ensure that these issues are resolved and
Bugzilla
CVE-2020-8620 bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
bugzilla·2020-08-18·CVSS 7.5
CVE-2020-8620 [HIGH] CVE-2020-8620 bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
CVE-2020-8620 bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c
As per upstream advisory:
In versions of BIND that use the libuv network manager (9.16.x is the only stable branch affected) an incorrectly specified maximum buffer size allows a specially crafted large TCP payload to trigger an assertion failure when it is received.
An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Discussion:
Acknowledgments:
Name: ISC
Upstream: Emanuel Almeida (Cisco Systems, Inc)
---
Statement:
This version only affects bind-9.16.x. Therefore versions of bind package shipped with Red Hat Enterprise Linux are not affected by this flaw.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8620https://security.gentoo.org/glsa/202008-19https://security.netapp.com/advisory/ntap-20200827-0003/https://usn.ubuntu.com/4468-1/https://www.synology.com/security/advisory/Synology_SA_20_19http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8620https://security.gentoo.org/glsa/202008-19https://security.netapp.com/advisory/ntap-20200827-0003/https://usn.ubuntu.com/4468-1/https://www.synology.com/security/advisory/Synology_SA_20_19
2020-08-21
Published