CVE-2020-8623: A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: be running BIND that was built with "--enable-native-pkcs11" be signing one or more zones with an RSA key be able to receive queries from a possible attacker
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-8623?
CVE-2020-8623 is a vulnerability in BIND DNS software that allows an attacker to crash a vulnerable system with a specially crafted query packet.
Which versions of BIND are affected by CVE-2020-8623?
BIND versions 9.10.0 to 9.11.21, 9.12.0 to 9.16.5, and 9.17.0 to 9.17.3 are affected by CVE-2020-8623.
How can an attacker exploit the CVE-2020-8623 vulnerability?
An attacker can exploit the CVE-2020-8623 vulnerability by sending a specially crafted query packet to a vulnerable BIND DNS server.
What is the severity of CVE-2020-8623?
CVE-2020-8623 has a severity score of 7.5 (High).
Are there any references for CVE-2020-8623?
Yes, you can find references for CVE-2020-8623 at the following links: [Link 1](https://kb.isc.org/docs/cve-2020-8623), [Link 2](https://gitlab.isc.org/isc-projects/bind9/commit/ac3862a5da95bb07b6cf748b0958175687a9de1d), [Link 3](https://gitlab.isc.org/isc-projects/bind9/commit/8d807cc21655eaa6e6a08afafeec3682c0f3f2ab).