CVE-2021-25220

Name
CVE-2021-25220
Description
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://kb.isc.org/v1/docs/cve-2021-25220
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYD7US4HZRFUGAJ66ZTHFBYVP5N3OQBY/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/API7U5E7SX7BAAVFNW366FFJGD6NZZKV/
CONFIRM https://security.netapp.com/advisory/ntap-20220408-0001/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5VX3I2U3ICOIEI5Y7OYA6CHOLFMNH3YQ/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SXT7247QTKNBQ67MNRGZD23ADXU6E5U/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DE3UAVCPUMAKG27ZL5YXSP2C3RIOW3JZ/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* bind >= 9.11.0 < 9.11.37
cpe:2.3:a:isc:bind:*:*:*:*:supported_preview:*:*:* bind >= 9.11.4 < 9.11.37
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* bind >= 9.12.0 < 9.16.27
cpe:2.3:a:isc:bind:*:*:*:*:supported_preview:*:*:* bind >= 9.16.8 < 9.16.27
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* bind >= 9.17.0 <= 9.18.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status