Internet Systems Consortium BIND server 9.15.6版本至9.16.5版本,9.17.0版本至 9.17.3版本中存在安全漏洞,该漏洞源于在通过libuv流量处理TCP流量时,如果对该服务器的TCP端口(用于处理较大的DNS请求(AXFR))发送大量数据包,程序会将长度值传入到服务器,造成断言失败。攻击者可通过向该端口发送大量未认证的数据包利用该漏洞造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-8621 | 7.5 HIGH | Attempting QNAME minimization after forwarding can lead to an assertion failure in resolve |
| CVE-2020-8623 | 7.5 HIGH | A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11 |
| CVE-2020-8622 | 6.5 MEDIUM | A truncated TSIG response can lead to an assertion failure |
| CVE-2020-8624 | 4.3 MEDIUM | update-policy rules of type "subdomain" are enforced incorrectly |
No comments yet