Files
CVEs-PoC/2020/CVE-2020-8624.md
T
2024-05-25 21:48:12 +02:00

19 lines
1.4 KiB
Markdown

### [CVE-2020-8624](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8624)
![](https://img.shields.io/static/v1?label=Product&message=BIND9&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3E%3D%209.9.12%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Change%204885%20inadvertently%20caused%20%22update-policy%22%20rules%20of%20type%20%22subdomain%22%20to%20be%20treated%20as%20if%20they%20were%20of%20type%20%22zonesub%22%2C%20allowing%20updates%20to%20all%20parts%20of%20the%20zone%20along%20with%20the%20intended%20subdomain.%20%20Affects%20BIND%209.9.12%20-%3E%209.9.13%2C%209.10.7%20-%3E%209.10.8%2C%209.11.3%20-%3E%209.11.21%2C%209.12.1%20-%3E%209.16.5%2C%209.17.0%20-%3E%209.17.3%2C%20also%20affects%209.9.12-S1%20-%3E%209.9.13-S1%2C%209.11.3-S1%20-%3E%209.11.21-S1%20of%20the%20BIND%209%20Supported%20Preview%20Edition&color=brighgreen)
### Description
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/fokypoky/places-list