Related Vulnerabilities: CVE-2020-8618  

An assertion check in BIND before 9.16.4 (that is meant to prevent going beyond the end of a buffer when processing incoming data) can be incorrectly triggered by a large response during zone transfer. An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

Severity Medium

Remote Yes

Type Denial of service

Description

An assertion check in BIND before 9.16.4 (that is meant to prevent going beyond the end of a buffer when processing incoming data) can be incorrectly triggered by a large response during zone transfer. An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

AVG-1191 bind 9.16.3-1 9.16.4-1 Medium Fixed

https://kb.isc.org/docs/cve-2020-8618
https://github.com/isc-projects/bind9/commit/c3dcab5f13547b397110b960d0840406fa958f50