Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2020-8619

Published: 17 June 2020

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

Notes

AuthorNote
mdeslaur
upstream advisory says BIND 9.11.14 -> 9.11.19, probably
introduced in race condition fixes introduced in 9.11.4.

Priority

Medium

Cvss 3 Severity Score

4.9

Score breakdown

Status

Package Release Status
bind9
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(1:9.11.3+dfsg-1ubuntu1.12)
eoan Not vulnerable
(1:9.11.5.P4+dfsg-5.1ubuntu2.2)
focal
Released (1:9.16.1-0ubuntu2.2)
trusty Not vulnerable

upstream
Released (9.11.20,9.16.4)
xenial Not vulnerable
(1:9.10.3.dfsg.P4-8ubuntu1.16)

Severity score breakdown

Parameter Value
Base score 4.9
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H