CVE-2020-8622: A truncated TSIG response can lead to an assertion failure
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.
Other sources
ISC BIND is vulnerable to a denial of service, caused by an assertion failure when attempting to verify a truncated response to a TSIG-signed request. By sending a specially-crafted request, a remote authenticated attacker could exploit this vulnerability to cause the server to exit.
— IBM
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8622?
The severity of CVE-2020-8622 is medium.
How does CVE-2020-8622 affect ISC BIND?
CVE-2020-8622 affects ISC BIND versions 9.0.0 to 9.11.21, 9.12.0 to 9.16.5, and 9.17.0 to 9.17.3.
How can an attacker exploit CVE-2020-8622?
An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering a denial of service.
Which software versions are affected by CVE-2020-8622?
ISC BIND versions 9.0.0 to 9.11.21, 9.12.0 to 9.16.5, and 9.17.0 to 9.17.3 are affected by CVE-2020-8622.
Where can I find more information about CVE-2020-8622?
You can find more information about CVE-2020-8622 in the references provided: [link1](http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html), [link2](http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html), [link3](https://kb.isc.org/docs/cve-2020-8622).