CVE-2021-25215 (CNNVD-202104-2109)

HIGH
中文标题:
ISC BIND 安全漏洞
英文标题:
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
CVSS分数: 7.5
发布时间: 2021-04-29 00:55:16
漏洞类型: 其他
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND 存在安全漏洞,该漏洞源于回答DNAME的查询时,断言检查可能会失败 需要处理DNAME才能解决的记录。

英文描述:

In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.

CWE类型:
CWE-617
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
ISC BIND9 Open Source Branches 9.0 through 9.11 9.0.0 through versions before 9.11.30 - - cpe:2.3:a:isc:bind9:open_source_branches_9.0_through_9.11_9.0.0_through_versions_before_9.11.30:*:*:*:*:*:*:*
ISC BIND9 Open Source Branches 9.12 through 9.16 9.12.0 through versions before 9.16.14 - - cpe:2.3:a:isc:bind9:open_source_branches_9.12_through_9.16_9.12.0_through_versions_before_9.16.14:*:*:*:*:*:*:*
ISC BIND9 Supported Preview Branches 9.9-S through 9.11-S 9.9.3-S1 through versions before 9.11.30-S1 - - cpe:2.3:a:isc:bind9:supported_preview_branches_9.9-s_through_9.11-s_9.9.3-s1_through_versions_before_9.11.30-s1:*:*:*:*:*:*:*
ISC BIND9 Supported Preview Branch 9.16-S 9.16.8-S1 through versions before 9.16.14-S1 - - cpe:2.3:a:isc:bind9:supported_preview_branch_9.16-s_9.16.8-s1_through_versions_before_9.16.14-s1:*:*:*:*:*:*:*
ISC BIND9 Development Branch 9.17 9.17.0 through versiosn before 9.17.12 - - cpe:2.3:a:isc:bind9:development_branch_9.17_9.17.0_through_versiosn_before_9.17.12:*:*:*:*:*:*:*
debian debian_linux 9.0 - - cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
debian debian_linux 10.0 - - cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
isc bind * - - cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
isc bind 9.9.3 - - cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:*
isc bind 9.9.12 - - cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:*
isc bind 9.9.13 - - cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:*
isc bind 9.10.5 - - cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:*
isc bind 9.10.7 - - cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*
isc bind 9.11.3 - - cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:*
isc bind 9.11.5 - - cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*
isc bind 9.11.6 - - cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:*
isc bind 9.11.7 - - cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:*
isc bind 9.11.8 - - cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:*
isc bind 9.11.12 - - cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:*
isc bind 9.11.21 - - cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:*
isc bind 9.11.27 - - cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:*
isc bind 9.11.29 - - cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:*
isc bind 9.16.8 - - cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:*
isc bind 9.16.11 - - cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:*
isc bind 9.16.13 - - cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:*
fedoraproject fedora 33 - - cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
fedoraproject fedora 34 - - cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
netapp active_iq_unified_manager - - - cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
netapp cloud_backup - - - cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
netapp h300s_firmware - - - cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
netapp h500s_firmware - - - cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
netapp h700s_firmware - - - cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
netapp h300e_firmware - - - cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
netapp h500e_firmware - - - cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
netapp h700e_firmware - - - cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
netapp h410s_firmware - - - cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
netapp a250_firmware - - - cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*
netapp 500f_firmware - - - cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*
oracle tekelec_platform_distribution * - - cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*
siemens sinec_infrastructure_network_services * - - cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 x_refsource_CONFIRM
cve.org
访问
[oss-security] 20210428 ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216) mailing-list
cve.org
访问
[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216) mailing-list
cve.org
访问
[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216) mailing-list
cve.org
访问
[oss-security] 20210429 Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216) mailing-list
cve.org
访问
DSA-4909 vendor-advisory
cve.org
访问
[debian-lts-announce] 20210504 [SECURITY] [DLA 2647-1] bind9 security update mailing-list
cve.org
访问
FEDORA-2021-ace61cbee1 vendor-advisory
cve.org
访问
FEDORA-2021-47f23870ec vendor-advisory
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
无标题 x_refsource_CONFIRM
cve.org
访问
无标题 x_refsource_CONFIRM
cve.org
访问
CVSS评分详情
3.1 (cna)
HIGH
7.5
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
机密性
NONE
完整性
NONE
可用性
HIGH
时间信息
发布时间:
2021-04-29 00:55:16
修改时间:
2024-09-16 22:02:24
创建时间:
2025-11-11 15:36:43
更新时间:
2025-11-11 15:56:42
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2021-25215 2025-11-11 15:20:51 2025-11-11 07:36:43
NVD nvd_CVE-2021-25215 2025-11-11 14:57:36 2025-11-11 07:45:03
CNNVD cnnvd_CNNVD-202104-2109 2025-11-11 15:10:37 2025-11-11 07:56:42
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:56:42
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-202104-2109; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 其他
  • cnnvd_id: 未提取 -> CNNVD-202104-2109
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:45:03
affected_products_count: 5 → 40; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • affected_products_count: 5 -> 40
  • data_sources: ['cve'] -> ['cve', 'nvd']