CVE-2020-8620: High severity ISC BIND vulnerability
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-8620?
CVE-2020-8620 is a vulnerability in BIND, a DNS software, that allows an attacker who can establish a TCP connection with the server to trigger an assertion failure and cause the server to exit.
What is the severity of CVE-2020-8620?
The severity of CVE-2020-8620 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-8620?
BIND versions 9.15.6 to 9.16.5 and 9.17.0 to 9.17.3 are affected by CVE-2020-8620.
How can an attacker exploit CVE-2020-8620?
An attacker who can establish a TCP connection with the vulnerable server can exploit CVE-2020-8620 by sending data on that connection to trigger the assertion failure.
Are there any references related to CVE-2020-8620?
Yes, you can find more information about CVE-2020-8620 in the following references: - http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html - http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html - https://kb.isc.org/docs/cve-2020-8620