An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
2020-06-17T22:15:12.977
2024-11-21T05:39:08.120
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | isc | bind | ≤ 9.16.3 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |
| Operating System | opensuse | leap | 15.2 | Yes |
| Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
| Operating System | canonical | ubuntu_linux | 20.04 | Yes |