Vulnerability Database

296,147

Total vulnerabilities in the database

CVE-2020-8623

In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker

  • Published: Aug 21, 2020
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-8623
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
isc / bind 9.17.0 9.17.3.x
isc / bind 9.12.1 9.16.5.x
isc / bind 9.10.0 9.11.21.x
isc / bind 9.10.5-s1 9.10.5-s1.x
isc / bind 9.11.21-s1 9.11.21-s1.x
fedoraproject / fedora 31 31.x
fedoraproject / fedora 32 32.x
opensuse / leap 15.1 15.1.x
opensuse / leap 15.2 15.2.x
debian / debian_linux 9.0 9.0.x
debian / debian_linux 10.0 10.0.x
canonical / ubuntu_linux 18.04 18.04.x
canonical / ubuntu_linux 20.04 20.04.x
canonical / ubuntu_linux 16.04 16.04.x
synology / dns_server - 2.2.2-5027