CVE-2021-25214
29.04.2021, 01:15
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.Enginsight
Vendor | Product | Version |
---|---|---|
isc | bind | 9.8.5 ≤ 𝑥 ≤ 9.8.8 |
isc | bind | 9.9.3 ≤ 𝑥 < 9.11.31 |
isc | bind | 9.12.0 ≤ 𝑥 < 9.16.15 |
isc | bind | 9.17.0 ≤ 𝑥 < 9.17.12 |
isc | bind | 9.9.3:s1 |
isc | bind | 9.9.12:s1 |
isc | bind | 9.9.13:s1 |
isc | bind | 9.10.5:s1 |
isc | bind | 9.10.7:s1 |
isc | bind | 9.11.3:s1 |
isc | bind | 9.11.5:s3 |
isc | bind | 9.11.5:s5 |
isc | bind | 9.11.5:s6 |
isc | bind | 9.11.6:s1 |
isc | bind | 9.11.7:s1 |
isc | bind | 9.11.8:s1 |
isc | bind | 9.11.12:s1 |
isc | bind | 9.11.21:s1 |
isc | bind | 9.11.27:s1 |
isc | bind | 9.11.29:s1 |
isc | bind | 9.16.8:s1 |
isc | bind | 9.16.11:s1 |
isc | bind | 9.16.13:s1 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
siemens | sinec_infrastructure_network_services | 𝑥 < 1.0.1.1 |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | aff_a250_firmware | - |
netapp | aff_500f_firmware | - |
netapp | h300s_firmware | - |
netapp | h500s_firmware | - |
netapp | h700s_firmware | - |
netapp | h300e_firmware | - |
netapp | h500e_firmware | - |
netapp | h700e_firmware | - |
netapp | h410s_firmware | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
bind9 |
|
Common Weakness Enumeration
References