2020年8月29日 星期六

[USN-4468-1] Bind vulnerabilities

 ---------- Forwarded message ---------

From: Marc Deslauriers <marc.deslauriers@canonical.com>

Date: Aug 21, 2020 9:58PM

Emanuel Almeida discovered that Bind incorrectly handled certain TCP

payloads. A remote attacker could possibly use this issue to cause Bind to

crash, resulting in a denial of service. This issue only affected Ubuntu

20.04 LTS. (CVE-2020-8620)

Joseph Gullo discovered that Bind incorrectly handled QNAME minimization

when used in certain configurations. A remote attacker could possibly use

this issue to cause Bind to crash, resulting in a denial of service. This

issue only affected Ubuntu 20.04 LTS. (CVE-2020-8621)

Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind

incorrectly handled certain truncated responses to a TSIG-signed request. A

remote attacker could possibly use this issue to cause Bind to crash,

resulting in a denial of service. (CVE-2020-8622)

Lyu Chiy discovered that Bind incorrectly handled certain queries. A remote

attacker could possibly use this issue to cause Bind to crash, resulting in

a denial of service. (CVE-2020-8623)

Joop Boonen discovered that Bind incorrectly handled certain subdomain

update-policy rules. A remote attacker granted privileges to change certain

parts of a zone could use this issue to change other contents of the zone,

contrary to expectations. This issue only affected Ubuntu 18.04 LTS and

Ubuntu 20.04 LTS. (CVE-2020-8624)

References:

  https://usn.ubuntu.com/4468-1

  CVE-2020-8620, CVE-2020-8621, CVE-2020-8622, CVE-2020-8623,

  CVE-2020-8624

沒有留言:

張貼留言