Lucene search

K
ibmIBMF847189F837954832A5D4C79716968441854E0CF05BFA8740F540844BB54683A
HistoryJun 17, 2021 - 7:03 p.m.

Security Bulletin: BIND for IBM i is affected by CVE-2021-25214 and CVE-2021-25215

2021-06-1719:03:16
www.ibm.com
35
ibm i
bind
cve-2021-25214
cve-2021-25215
ptf
denial of service
ixfr
dname
assertion failure

EPSS

0.067

Percentile

93.9%

Summary

BIND is used by IBM i. IBM i has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2021-25214
**DESCRIPTION:**ISC BIND is vulnerable to a denial of service, caused by a broken inbound incremental zone update (IXFR). By sending a specially crafted IXFR, an attacker could exploit this vulnerability to trigger a failed assertion check and terminate the named process.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/200961 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2021-25215
**DESCRIPTION:**ISC BIND is vulnerable to a denial of service, caused by an assertion failure while answering queries for DNAME records. By sending a query for DNAME records, an attacker could exploit this vulnerability to trigger a failed assertion check and terminate the named process.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/200960 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM i 7.4
IBM i 7.3
IBM i 7.2
IBM i 7.1

Remediation/Fixes

The issues can be fixed by applying a PTF to IBM i. Releases 7.4, 7.3, 7.2, and 7.1 of IBM i are supported and will be fixed.

The IBM i PTF numbers are:
**Release 7.4 – SI76268 ****Release 7.3 – SI76269 ****Release 7.2 – SI76272 **Release 7.1 – SI76273

<https://www.ibm.com/support/fixcentral/&gt;

_Important note: __IBM recommends that all users running unsupported versions of affected products upgrade to supported and fixed version of affected products.
_

Workarounds and Mitigations

None