CVE-2021-25214 - Reachable Assertion

Severity

65%

Complexity

27%

Confidentiality

60%

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.

CVSS 3.1 Base Score 6.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS 2.0 Base Score 4. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).

Demo Examples

Reachable Assertion

CWE-617

In the excerpt below, an AssertionError (an unchecked exception) is thrown if the user hasn't entered an email address in an HTML form.


               
assert email != null;

Overview

First reported 3 years ago

2021-04-29 01:15:00

Last updated 3 years ago

2021-05-21 09:15:00

Affected Software

ISC BIND 9.9.3 S1 Supported Preview Edition

9.9.3

ISC BIND 9.10.5 S1 Supported Preview Edition

9.10.5

ISC BIND 9.10.7 S1 Supported Preview Edition

9.10.7

ISC BIND 9.11.3 S1 Supported Preview Edition

9.11.3

ISC BIND 9.11.5 S3 Supported Preview Edition

9.11.5

ISC BIND 9.11.5 S5 Supported Preview Edition

9.11.5

ISC BIND 9.11.6 S1 Supported Preview Edition

9.11.6

ISC BIND 9.11.7 S1 Supported Preview Edition

9.11.7

Debian Linux 9.0

9.0

References

https://kb.isc.org/v1/docs/cve-2021-25214

[oss-security] 20210428 ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

DSA-4909

[debian-lts-announce] 20210504 [SECURITY] [DLA 2647-1] bind9 security update

FEDORA-2021-ace61cbee1

FEDORA-2021-47f23870ec

https://kb.isc.org/v1/docs/cve-2021-25214

Vendor Advisory

[oss-security] 20210428 ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

DSA-4909

Third Party Advisory

[debian-lts-announce] 20210504 [SECURITY] [DLA 2647-1] bind9 security update

Mailing List, Third Party Advisory

FEDORA-2021-ace61cbee1

Mailing List, Third Party Advisory

FEDORA-2021-47f23870ec

Mailing List, Third Party Advisory

https://security.netapp.com/advisory/ntap-20210521-0006/

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.