Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-25220
HistoryMar 16, 2022 - 12:00 a.m.

CVE-2021-25220

2022-03-1600:00:00
ubuntu.com
ubuntu.com
30
bind 9.11.x
9.12.x
9.16.x
9.17.x
9.18.x
cache poisoning
incorrect records
dns

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

EPSS

0.002

Percentile

54.6%

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported
Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions
of BIND 9 earlier than those shown - back to 9.1.0, including Supported
Preview Editions - are also believed to be affected but have not been
tested as they are EOL. The cache could become poisoned with incorrect
records leading to queries being made to the wrong servers, which might
also result in false information being returned to clients.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchbind9< 1:9.11.3+dfsg-1ubuntu1.17UNKNOWN
ubuntu20.04noarchbind9< 1:9.16.1-0ubuntu2.10UNKNOWN
ubuntu21.10noarchbind9< 1:9.16.15-1ubuntu1.2UNKNOWN
ubuntu22.04noarchbind9< 1:9.18.0-2ubuntu3UNKNOWN
ubuntu14.04noarchbind9< 1:9.9.5.dfsg-3ubuntu0.19+esm6UNKNOWN
ubuntu16.04noarchbind9< 1:9.10.3.dfsg.P4-8ubuntu1.19+esm2UNKNOWN

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

EPSS

0.002

Percentile

54.6%