Files
CVEs-PoC/2020/CVE-2020-8623.md
T
2024-05-25 21:48:12 +02:00

19 lines
1.3 KiB
Markdown

### [CVE-2020-8623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8623)
![](https://img.shields.io/static/v1?label=Product&message=BIND9&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3E%3D%209.10.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=If%20BIND%20is%20built%20with%20%22--enable-native-pkcs11%22%20then%20a%20specially%20crafted%20query%20for%20a%20zone%20signed%20with%20RSA%20can%20trigger%20an%20assertion%20failure.%20%20Affects%20BIND%209.10.0%20-%3E%209.11.21%2C%209.12.0%20-%3E%209.16.5%2C%209.17.0%20-%3E%209.17.3%2C%20also%20affects%209.10.5-S1%20-%3E%209.11.21-S1%20of%20the%20BIND%209%20Supported%20Preview%20Edition&color=brighgreen)
### Description
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/fokypoky/places-list