[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1426 --- bind

ID: oval:org.secpod.oval:def:1700337Date: (C)2020-05-26   (M)2023-12-20
Class: PATCHFamily: unix




An assertion failure was found in BIND, which checks the validity of messages containing TSIG resource records. This flaw allows an attacker that knows or successfully guesses the name of the TSIG key used by the server to use a specially-crafted message, potentially causing a BIND server to reach an inconsistent state or cause a denial of service. A majority of BIND servers have an internally-generated TSIG session key whose name is trivially guessable, and that key exposes the vulnerability unless specifically disabled. A flaw was found in BIND, where it does not sufficiently limit the number of fetches that can be performed while processing a referral response. This flaw allows an attacker to cause a denial of service attack. The attacker can also exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor

Platform:
Amazon Linux 2
Product:
bind
Reference:
ALAS2-2020-1426
CVE-2020-8616
CVE-2020-8617
CVE    2
CVE-2020-8617
CVE-2020-8616

© SecPod Technologies