CVE-2020-8619: A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8619?
The severity of CVE-2020-8619 is medium with a CVSS score of 4.9.
What is the affected software for CVE-2020-8619?
The affected software for CVE-2020-8619 includes ISC BIND versions 9.11.14 to 9.11.19, 9.14.9 to 9.14.12, 9.16.0 to 9.16.3, and BIND Supported Preview Edition 9.11.14-S1 to 9.11.19-S1.
How can I fix CVE-2020-8619?
To fix CVE-2020-8619, you should update ISC BIND to versions 9.11.20, 9.14.13, or 9.16.4 and ensure that you are using the latest stable release of BIND.
Where can I find more information about CVE-2020-8619?
You can find more information about CVE-2020-8619 on the ISC Knowledge Base and the ISC BIND GitLab repository.
What is the Common Weakness Enumeration (CWE) for CVE-2020-8619?
The Common Weakness Enumeration (CWE) for CVE-2020-8619 is CWE-404, which refers to improper resource shutdown or release.