CVE-2021-25215 - Reachable Assertion

Severity

75%

Complexity

39%

Confidentiality

60%

In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.

CVSS 3.1 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS 2.0 Base Score 5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).

Demo Examples

Reachable Assertion

CWE-617

In the excerpt below, an AssertionError (an unchecked exception) is thrown if the user hasn't entered an email address in an HTML form.


               
assert email != null;

Overview

First reported 3 years ago

2021-04-29 01:15:00

Last updated 3 years ago

2021-12-08 20:13:00

Affected Software

Debian Linux 9.0

9.0

ISC BIND 9.9.3 S1 Supported Preview Edition

9.9.3

ISC BIND 9.10.5 S1 Supported Preview Edition

9.10.5

ISC BIND 9.10.7 S1 Supported Preview Edition

9.10.7

ISC BIND 9.11.3 S1 Supported Preview Edition

9.11.3

ISC BIND 9.11.5 S3 Supported Preview Edition

9.11.5

ISC BIND 9.11.5 S5 Supported Preview Edition

9.11.5

ISC BIND 9.11.6 S1 Supported Preview Edition

9.11.6

ISC BIND 9.11.7 S1 Supported Preview Edition

9.11.7

NetApp Active IQ Unified Manager for VMware vSphere

vmware_vsphere

References

https://kb.isc.org/v1/docs/cve-2021-25215

[oss-security] 20210428 ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

DSA-4909

[debian-lts-announce] 20210504 [SECURITY] [DLA 2647-1] bind9 security update

https://kb.isc.org/v1/docs/cve-2021-25215

Vendor Advisory

[oss-security] 20210428 ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)

Mailing List, Third Party Advisory

DSA-4909

Third Party Advisory

[debian-lts-announce] 20210504 [SECURITY] [DLA 2647-1] bind9 security update

Mailing List, Third Party Advisory

FEDORA-2021-ace61cbee1

Mailing List, Third Party Advisory

FEDORA-2021-47f23870ec

https://security.netapp.com/advisory/ntap-20210521-0006/

https://www.oracle.com/security-alerts/cpuoct2021.html

FEDORA-2021-47f23870ec

Mailing List, Third Party Advisory

https://security.netapp.com/advisory/ntap-20210521-0006/

Third Party Advisory

https://www.oracle.com/security-alerts/cpuoct2021.html

Patch, Third Party Advisory

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.