Zero-friction vulnerability management platform

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

ISC BIND Multiple DoS Vulnerabilities - CVE-2020-8622, CVE-2020-8623 (Windows)

Information

Severity

Severity

High

Family

Family

Denial of Service

CVSSv2 Base

CVSSv2 Base

7.8

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

ISC BIND is prone to multiple denial of service vulnerabilities.

Insight

Insight

The following vulnerabilities exist: - A truncated TSIG response can lead to an assertion failure (CVE-2020-8622) - A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c (CVE-2020-8623)

Affected Software

Affected Software

BIND 9.10.0 - 9.11.21, 9.12.0 - 9.16.5, 9.17.0 - 9.17.3 and 9.10.5-S1 - 9.11.21-S1.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Update to version 9.11.22, 9.16.6, 9.17.4, 9.11.22-S1 or later.

Common Vulnerabilities and Exposures (CVE)