4
CVSSv2

CVE-2020-8618

Published: 17/06/2020 Updated: 07/10/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

It exists that Bind incorrectly handled large responses during zone transfers. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2020-8618)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind

opensuse leap 15.1

opensuse leap 15.2

netapp steelstore cloud integrated storage -

canonical ubuntu linux 20.04

Vendor Advisories

Bind could be made to crash if it received specially crafted network traffic ...
An assertion check in BIND before 9164 (that is meant to prevent going beyond the end of a buffer when processing incoming data) can be incorrectly triggered by a large response during zone transfer An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a ...