6.5

CVE-2021-25214

A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind SwEdition - Version >= 9.8.5 <= 9.8.8
Isc ≫ Bind SwEdition - Version >= 9.9.3 < 9.11.31
Isc ≫ Bind SwEdition - Version >= 9.12.0 < 9.16.15
Isc ≫ Bind SwEdition - Version >= 9.17.0 < 9.17.12
Isc ≫ Bind Version 9.9.3 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.9.12 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.9.13 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.10.5 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.10.7 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.3 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s3 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s5 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s6 SwEdition supported_preview
Isc ≫ Bind Version 9.11.6 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.7 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.8 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.12 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.21 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.27 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.29 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.8 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.11 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.13 Update s1 SwEdition supported_preview
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vsphere
Netapp ≫ Cloud Backup Version -
Netapp ≫ Aff A250 Firmware Version -
   Netapp ≫ Aff A250 Version -
Netapp ≫ Aff 500f Firmware Version -
   Netapp ≫ Aff 500f Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.99% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
ISC 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Patch
Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/1
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2021/04/29/2
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2021/04/29/3
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2021/04/29/4
Third Party Advisory
Mailing List
https://kb.isc.org/v1/docs/cve-2021-25214
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/
https://security.netapp.com/advisory/ntap-20210521-0006/
Third Party Advisory
https://www.debian.org/security/2021/dsa-4909
Third Party Advisory