Lucene search

K
osvGoogleOSV:USN-4929-1
HistoryApr 29, 2021 - 11:11 a.m.

bind9 vulnerabilities

2021-04-2911:11:53
Google
osv.dev
30
bind9
vulnerabilities
zone updates
dname records
gssapi
remote attacker
denial of service
arbitrary code

AI Score

7.8

Confidence

High

EPSS

0.447

Percentile

97.4%

Greg Kuechle discovered that Bind incorrectly handled certain incremental
zone updates. A remote attacker could possibly use this issue to cause Bind
to crash, resulting in a denial of service. (CVE-2021-25214)

Siva Kakarla discovered that Bind incorrectly handled certain DNAME
records. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. (CVE-2021-25215)

It was discovered that Bind incorrectly handled GSSAPI security policy
negotiation. A remote attacker could use this issue to cause Bind to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-25216)