← Back

CVE-2020-8625

nvd nist
Published: Feb 17, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. The most likely outcome of a successful exploitation of the vulnerability is a crash of the named process. However, remote code execution, while unproven, is theoretically possible. Affects: BIND 9.5.0 -> 9.11.27, 9.12.0 -> 9.16.11, and versions BIND 9.11.3-S1 -> 9.11.27-S1 and 9.16.8-S1 -> 9.16.11-S1 of BIND Supported Preview Edition. Also release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch

Affected (23)

Products: Isc: Bind · Debian: Debian Linux · Fedoraproject: Fedora · +2 more
Show all products
1 product
Bind
1 product
Debian Linux
1 product
Fedora
1 product
3 products
Cloud Backup
A250 Firmware
500f Firmware
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Isc
From 9.12.0 to 9.16.11
From 9.5.0 to 9.11.27
Version 9.11.21 s1
Version 9.11.27 s1
Version 9.11.3 s1
Version 9.11.5 s3
Version 9.11.5 s5
Version 9.11.6 s1
Version 9.11.7 s1
Version 9.11.8 s1
Version 9.16.11 s1
Version 9.16.8 s1
Version 9.17.0
Version 9.17.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.1.1
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
A250
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
500f
All versions

References (22)

Source: security-officer@isc.org
Mailing ListPatchThird Party Advisory
Source: security-officer@isc.org
Mailing ListPatchThird Party Advisory
Source: security-officer@isc.org
PatchThird Party Advisory
Source: security-officer@isc.org
MitigationVendor Advisory
Source: security-officer@isc.org
Mailing ListThird Party Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Third Party Advisory
Source: security-officer@isc.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.