Red Hat Security Advisory: bind security, bug fix, and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-8619 — bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c CVE-2020-8622 — bind: truncated TSIG response can lead to an assertion failure CVE-2020-8623 — bind: remotely triggerable assertion failure in pk11.c CVE-2020-8624 — bind: incorrect enforcement of update-policy rules of type "subdomain"
🎯 Affected products173
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux BaseOS (v. 8)
- bind-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-32:9.11.20-5.el8.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-chroot-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-chroot-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-chroot-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-chroot-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debuginfo-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debugsource-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debugsource-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debugsource-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debugsource-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debugsource-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debugsource-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debugsource-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bind-debugsource-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bind-debugsource-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +143 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, the BIND daemon (named) will be restarted automatically. Workaround: As per upstream advisory: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2020:4500
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1693395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1749505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814158
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817870
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1847244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1859454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869477
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869480
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4500.json