Alibaba Cloud Linux 3 : 0025: bind (ALINUX3-SA-2021:0025)

high Nessus Plugin ID 236577

Synopsis

The remote Alibaba Cloud Linux host is missing one or more security updates.

Description

The remote Alibaba Cloud Linux 3 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALINUX3-SA-2021:0025 advisory.

Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities:

CVE-2019-6465:
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.

CVE-2019-6471:
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.

CVE-2020-8617:
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.

CVE-2020-8622:
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.

CVE-2020-8623:
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with
--enable-native-pkcs11 * be signing one or more zones with an RSA key * be able to receive queries from a possible attacker

CVE-2020-8624:
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.

CVE-2020-8625:
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options. Although the default configuration is not vulnerable, GSS- TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. The most likely outcome of a successful exploitation of the vulnerability is a crash of the named process. However, remote code execution, while unproven, is theoretically possible. Affects: BIND 9.5.0 -> 9.11.27, 9.12.0 -> 9.16.11, and versions BIND 9.11.3-S1 -> 9.11.27-S1 and 9.16.8-S1 -> 9.16.11-S1 of BIND Supported Preview Edition.
Also release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch

Tenable has extracted the preceding description block directly from the Alibaba Cloud Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://mirrors.aliyun.com/alinux/3/cve/alinux3-sa-20210025.xml

Plugin Details

Severity: High

ID: 236577

File Name: alinux3_sa_2021-0025.nasl

Version: 1.1

Type: local

Published: 5/14/2025

Updated: 5/14/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-8625

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11-libs-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-export-libs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:python3-bind, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-utils-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11-utils-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-license, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-export-devel, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-libs-lite, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-devel, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-libs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-utils, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-sdb, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-libs-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-export-libs-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11-devel, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-sdb-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11-utils, cpe:/o:alibabacloud:alibaba_cloud_linux_3, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11-libs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-chroot, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-libs-lite-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-pkcs11, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-sdb-chroot, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-debugsource, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:bind-lite-devel

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Alibaba/release, Host/Alibaba/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/12/2021

Vulnerability Publication Date: 2/21/2019

Reference Information

CVE: CVE-2019-6465, CVE-2019-6471, CVE-2020-8617, CVE-2020-8622, CVE-2020-8623, CVE-2020-8624, CVE-2020-8625