CVE-2020-8621: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8621?
The severity of CVE-2020-8621 is high with a severity value of 7.5.
Which versions of BIND are affected by CVE-2020-8621?
BIND versions 9.14.0 to 9.16.5 and 9.17.0 to 9.17.3 are affected by CVE-2020-8621.
How can an attacker exploit CVE-2020-8621?
An attacker can exploit CVE-2020-8621 by sending queries to a BIND server configured with both QNAME minimization and 'forward first', causing the server to crash.
Are servers configured with 'forward only' affected by CVE-2020-8621?
No, servers configured with 'forward only' are not affected by CVE-2020-8621.
How can I fix CVE-2020-8621?
To fix CVE-2020-8621, update your BIND server to a version that includes the fix for the vulnerability.