Lucene search

K
cloudlinuxCloudLinuxCLSA-2021:1632261705
HistorySep 21, 2021 - 10:01 p.m.

Fix of CVE: CVE-2021-25215, CVE-2021-25214, CVE-2021-25216

2021-09-2122:01:45
repo.cloudlinux.com
97
cve-2021-25215
bind
vulnerability
buffer overflow
gssapi
security policy
ixfr
named
assertion check
dname
records

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.447

Percentile

97.4%

  • A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly (CVE-2021-25214)
  • An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself (CVE-2021-25215)
  • A second vulnerability in BIND’s GSSAPI security policy negotiation can be targeted by a buffer overflow attack (CVE-2021-25216)

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.447

Percentile

97.4%