CVE-2021-25214

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.

References

https://kb.isc.org/v1/docs/cve-2021-25214

http://www.openwall.com/lists/oss-security/2021/04/29/1

http://www.openwall.com/lists/oss-security/2021/04/29/2

http://www.openwall.com/lists/oss-security/2021/04/29/3

http://www.openwall.com/lists/oss-security/2021/04/29/4

https://www.debian.org/security/2021/dsa-4909

https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/

https://lists.fedoraproject.org/archives/list/[email protected]/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/

https://security.netapp.com/advisory/ntap-20210521-0006/

Details

Source: MITRE

Published: 2021-04-29

Updated: 2021-05-21

Type: CWE-617

Risk Information

CVSS v2

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 2.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* versions from 9.8.5 to 9.8.8 (inclusive)

cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.5:s6:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:*

cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

Configuration 2

OR

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Tenable Plugins

View all (35 total)

IDNameProductFamilySeverity
155430Oracle Linux 8 : bind (ELSA-2021-4384)NessusOracle Linux Local Security Checks
medium
155208RHEL 8 : bind (RHSA-2021:4384)NessusRed Hat Local Security Checks
medium
154698F5 Networks BIG-IP : BIND vulnerability (K11426315)NessusF5 Networks Local Security Checks
medium
154393EulerOS 2.0 SP3 : bind (EulerOS-SA-2021-2572)NessusHuawei Local Security Checks
high
153289EulerOS 2.0 SP2 : bind (EulerOS-SA-2021-2354)NessusHuawei Local Security Checks
high
153067EulerOS 2.0 SP5 : bind (EulerOS-SA-2021-2320)NessusHuawei Local Security Checks
high
152979Oracle Linux 7 : bind (ELSA-2021-3325)NessusOracle Linux Local Security Checks
medium
152973CentOS 7 : bind (CESA-2021:3325)NessusCentOS Local Security Checks
medium
152952Scientific Linux Security Update : bind on SL7.x i686/x86_64 (2021:3325)NessusScientific Linux Local Security Checks
medium
152923RHEL 7 : bind (RHSA-2021:3325)NessusRed Hat Local Security Checks
medium
152309EulerOS 2.0 SP9 : bind (EulerOS-SA-2021-2236)NessusHuawei Local Security Checks
high
152299EulerOS 2.0 SP9 : bind (EulerOS-SA-2021-2262)NessusHuawei Local Security Checks
high
151729openSUSE 15 Security Update : bind (openSUSE-SU-2021:1826-1)NessusSuSE Local Security Checks
high
151543EulerOS Virtualization 2.9.0 : bind (EulerOS-SA-2021-2194)NessusHuawei Local Security Checks
high
151538EulerOS Virtualization 2.9.1 : bind (EulerOS-SA-2021-2180)NessusHuawei Local Security Checks
high
151313EulerOS Virtualization for ARM 64 3.0.2.0 : bind (EulerOS-SA-2021-2092)NessusHuawei Local Security Checks
high
151184EulerOS Virtualization for ARM 64 3.0.6.0 : bind (EulerOS-SA-2021-2013)NessusHuawei Local Security Checks
high
151039EulerOS 2.0 SP8 : bind (EulerOS-SA-2021-1975)NessusHuawei Local Security Checks
high
150971Amazon Linux 2 : bind (ALAS-2021-1651)NessusAmazon Linux Local Security Checks
medium
150646SUSE SLES11 Security Update : bind (SUSE-SU-2021:14714-1)NessusSuSE Local Security Checks
critical
150437Photon OS 4.0: Bindutils PHSA-2021-4.0-0039NessusPhotonOS Local Security Checks
critical
150215SUSE SLED15 / SLES15 Security Update : bind (SUSE-SU-2021:1826-1)NessusSuSE Local Security Checks
high
149950Photon OS 1.0: Bindutils PHSA-2021-1.0-0391NessusPhotonOS Local Security Checks
critical
149930Photon OS 3.0: Bindutils PHSA-2021-3.0-0240NessusPhotonOS Local Security Checks
critical
149926Photon OS 2.0: Bindutils PHSA-2021-2.0-0348NessusPhotonOS Local Security Checks
critical
149636openSUSE Security Update : bind (openSUSE-2021-668)NessusSuSE Local Security Checks
high
149320ISC BIND 9.8.5 < 9.11.31 / 9.9.3 < 9.11.31 / 9.9.3-S1 < 9.11.31-S1 / 9.12.0 < 9.16.15 / 9.16.8-S1 < 9.16.15-S1 / 9.17.0 < 9.17.12 Assertion Failure (CVE-2021-25214)NessusDNS
medium
149279SUSE SLES12 Security Update : bind (SUSE-SU-2021:1468-1)NessusSuSE Local Security Checks
high
149276SUSE SLED15 / SLES15 Security Update : bind (SUSE-SU-2021:1471-1)NessusSuSE Local Security Checks
high
149269SUSE SLES12 Security Update : bind (SUSE-SU-2021:1469-1)NessusSuSE Local Security Checks
critical
149262Debian DLA-2647-1 : bind9 security updateNessusDebian Local Security Checks
critical
149229Debian DSA-4909-1 : bind9 - security updateNessusDebian Local Security Checks
critical
149212ISC BIND Malformed IXFR DoS (CVE-2021-25214)NessusDNS
medium
149092Ubuntu 16.04 LTS / 18.04 LTS / 20.04 LTS / 20.10 / 21.04 : Bind vulnerabilities (USN-4929-1)NessusUbuntu Local Security Checks
critical
149067Slackware 14.0 / 14.1 / 14.2 / current : bind (SSA:2021-118-01)NessusSlackware Local Security Checks
critical