Files
CVEs-PoC/2020/CVE-2020-8622.md
T
2024-05-25 21:48:12 +02:00

26 lines
1.8 KiB
Markdown

### [CVE-2020-8622](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8622)
![](https://img.shields.io/static/v1?label=Product&message=BIND9&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3E%3D%209.0.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Attempting%20to%20verify%20a%20truncated%20response%20to%20a%20TSIG-signed%20request%20leads%20to%20an%20assertion%20failure.%20%20Affects%20BIND%209.0.0%20-%3E%209.11.21%2C%209.12.0%20-%3E%209.16.5%2C%209.17.0%20-%3E%209.17.3%2C%20also%20affects%209.9.3-S1%20-%3E%209.11.21-S1%20of%20the%20BIND%209%20Supported%20Preview%20Edition&color=brighgreen)
### Description
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.
### POC
#### Reference
- https://www.oracle.com/security-alerts/cpuoct2021.html
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/DButter/whitehat_public
- https://github.com/Dokukin1/Metasploitable
- https://github.com/Iknowmyname/Nmap-Scans-M2
- https://github.com/NikulinMS/13-01-hw
- https://github.com/Zhivarev/13-01-hw
- https://github.com/fokypoky/places-list
- https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems
- https://github.com/zzzWTF/db-13-01