cve/2020/CVE-2020-8618.md

18 lines
964 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-8618](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8618)
![](https://img.shields.io/static/v1?label=Product&message=BIND9&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=An%20assertion%20check%20in%20BIND%20(that%20is%20meant%20to%20prevent%20going%20beyond%20the%20end%20of%20a%20buffer%20when%20processing%20incoming%20data)%20can%20be%20incorrectly%20triggered%20by%20a%20large%20response%20during%20zone%20transfer.%20%20Versions%20affected%3A%20BIND%209.16.0%20-%3E%209.16.3&color=brighgreen)
### Description
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Live-Hack-CVE/CVE-2020-8618