CVE-2021-25220

Description

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.108

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2021-25220,CVE-2022-0396,CVE-2022-0635,CVE-2022-0667 are affected in BIND 9.18.0Windows
Vulnerabilities CVE-2021-25220 are affected in BIND 9.11.36Windows
Vulnerabilities CVE-2021-25220,CVE-2022-0396 are affected in BIND 9.16.26Windows
Vulnerabilities CVE-2021-25220,CVE-2022-0396,CVE-2022-0635,CVE-2022-0667 are affected in BIND 9.18.0Windows
bind9 security update(DSA-5105-1) bind9_9.16.27-1~deb11u1_amd64.debLinux
bind9 security update(DSA-5105-1) bind9_9.11.5.P4+dfsg-5.1+deb10u7_i386.debLinux
bind9 security update(DSA-5105-1) bind9_9.11.5.P4+dfsg-5.1+deb10u7_amd64.debLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-chrootenv-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-debugsource-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-doc-9.11.22-3.40.1.noarch.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-utils-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) bind-utils-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libbind9-161-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libbind9-161-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libdns1110-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libdns1110-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libirs161-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libirs161-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisc1107-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisc1107-32bit-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisc1107-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisc1107-debuginfo-32bit-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisccc161-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisccc161-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisccfg163-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) libisccfg163-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) liblwres161-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) liblwres161-debuginfo-9.11.22-3.40.1.x86_64.rpmLinux
SUSE-SU-2022:0908-1(SUSE Linux Enterprise Server 12-SP5 ) python-bind-9.11.22-3.40.1.noarch.rpmLinux
(RHSA-2022:7643) bind9.16 security update bind9.16-9.16.23-0.9.el8.1.x86_64.rpmLinux
(RHSA-2022:7643) bind9.16 security update bind9.16-chroot-9.16.23-0.9.el8.1.x86_64.rpmLinux
(RHSA-2022:7643) bind9.16 security update bind9.16-debugsource-9.16.23-0.9.el8.1.x86_64.rpmLinux
(RHSA-2022:7643) bind9.16 security update bind9.16-libs-9.16.23-0.9.el8.1.x86_64.rpmLinux
(RHSA-2022:7643) bind9.16 security update bind9.16-license-9.16.23-0.9.el8.1.noarch.rpmLinux
(RHSA-2022:7643) bind9.16 security update bind9.16-utils-9.16.23-0.9.el8.1.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-chroot-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-debugsource-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-debugsource-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-devel-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-devel-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-export-devel-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-export-devel-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-export-libs-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-export-libs-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-libs-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-libs-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-libs-lite-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-libs-lite-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-license-9.11.36-5.el8.noarch.rpmLinux
(RHSA-2022:7790) bind security update bind-lite-devel-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-lite-devel-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-pkcs11-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-pkcs11-devel-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-pkcs11-devel-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-pkcs11-libs-9.11.36-5.el8.i686.rpmLinux
(RHSA-2022:7790) bind security update bind-pkcs11-libs-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-pkcs11-utils-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-sdb-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-sdb-chroot-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update bind-utils-9.11.36-5.el8.x86_64.rpmLinux
(RHSA-2022:7790) bind security update python3-bind-9.11.36-5.el8.noarch.rpmLinux
Bind update (ELSA-2023-0402) bind-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-chroot update (ELSA-2023-0402) bind-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-export-libs update (ELSA-2023-0402) bind-export-libs-9.11.4-26.P2.el7_9.13.i686.rpmLinux
Bind-export-libs update (ELSA-2023-0402) bind-export-libs-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-libs update (ELSA-2023-0402) bind-libs-9.11.4-26.P2.el7_9.13.i686.rpmLinux
Bind-libs update (ELSA-2023-0402) bind-libs-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-libs-lite update (ELSA-2023-0402) bind-libs-lite-9.11.4-26.P2.el7_9.13.i686.rpmLinux
Bind-libs-lite update (ELSA-2023-0402) bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-license update (ELSA-2023-0402) bind-license-9.11.4-26.P2.el7_9.13.noarch.rpmLinux
Bind-pkcs11 update (ELSA-2023-0402) bind-pkcs11-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-pkcs11-libs update (ELSA-2023-0402) bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.i686.rpmLinux
Bind-pkcs11-libs update (ELSA-2023-0402) bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-pkcs11-utils update (ELSA-2023-0402) bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
Bind-utils update (ELSA-2023-0402) bind-utils-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-devel-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-devel-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-export-devel-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-export-devel-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-export-libs-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-export-libs-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-libs-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-libs-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-libs-lite-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-license-9.11.4-26.P2.el7_9.13.noarch.rpmLinux
(RHSA-2023:0402) bind security update bind-lite-devel-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-lite-devel-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-pkcs11-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-pkcs11-devel-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.i686.rpmLinux
(RHSA-2023:0402) bind security update bind-pkcs11-libs-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-pkcs11-utils-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-sdb-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-sdb-chroot-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2023:0402) bind security update bind-utils-9.11.4-26.P2.el7_9.13.x86_64.rpmLinux
(RHSA-2022:8068) bind security update bind-9.16.23-5.el9_1.x86_64.rpmLinux
(RHSA-2022:8068) bind security update bind-chroot-9.16.23-5.el9_1.x86_64.rpmLinux
(RHSA-2022:8068) bind security update bind-debugsource-9.16.23-5.el9_1.x86_64.rpmLinux
(RHSA-2022:8068) bind security update bind-dnssec-doc-9.16.23-5.el9_1.noarch.rpmLinux
(RHSA-2022:8068) bind security update bind-dnssec-utils-9.16.23-5.el9_1.x86_64.rpmLinux
(RHSA-2022:8068) bind security update bind-libs-9.16.23-5.el9_1.x86_64.rpmLinux
(RHSA-2022:8068) bind security update bind-license-9.16.23-5.el9_1.noarch.rpmLinux
(RHSA-2022:8068) bind security update bind-utils-9.16.23-5.el9_1.x86_64.rpmLinux
(RHSA-2022:8068) bind security update python3-bind-9.16.23-5.el9_1.noarch.rpmLinux
(RHSA-2022:8385) dhcp security and enhancement update dhcp-client-4.4.2-17.b1.el9.x86_64.rpmLinux
(RHSA-2022:8385) dhcp security and enhancement update dhcp-common-4.4.2-17.b1.el9.noarch.rpmLinux
(RHSA-2022:8385) dhcp security and enhancement update dhcp-debugsource-4.4.2-17.b1.el9.x86_64.rpmLinux
(RHSA-2022:8385) dhcp security and enhancement update dhcp-relay-4.4.2-17.b1.el9.x86_64.rpmLinux
(RHSA-2022:8385) dhcp security and enhancement update dhcp-server-4.4.2-17.b1.el9.x86_64.rpmLinux
bind9.16 security update (RLSA-2022:7643) bind9.16-9.16.23-0.9.el8.1.x86_64.rpmLinux
bind9.16 security update (RLSA-2022:7643) bind9.16-libs-9.16.23-0.9.el8.1.x86_64.rpmLinux
bind9.16 security update (RLSA-2022:7643) bind9.16-utils-9.16.23-0.9.el8.1.x86_64.rpmLinux
bind9.16 security update (RLSA-2022:7643) bind9.16-chroot-9.16.23-0.9.el8.1.x86_64.rpmLinux
bind9.16 security update (RLSA-2022:7643) bind9.16-license-9.16.23-0.9.el8.1.noarch.rpmLinux
bind security update (RLSA-2022:7790) bind-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-sdb-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-libs-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-libs-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-devel-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-devel-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-utils-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-chroot-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-pkcs11-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-license-9.11.36-5.el8_7.2.noarch.rpmLinux
bind security update (RLSA-2022:7790) python3-bind-9.11.36-5.el8_7.2.noarch.rpmLinux
bind security update (RLSA-2022:7790) bind-libs-lite-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-libs-lite-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-lite-devel-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-lite-devel-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-sdb-chroot-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-export-libs-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-export-libs-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-pkcs11-libs-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-pkcs11-libs-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-export-devel-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-export-devel-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-pkcs11-devel-9.11.36-5.el8_7.2.i686.rpmLinux
bind security update (RLSA-2022:7790) bind-pkcs11-devel-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:7790) bind-pkcs11-utils-9.11.36-5.el8_7.2.x86_64.rpmLinux
bind security update (RLSA-2022:8068) bind-9.16.23-5.el9_1.x86_64.rpmLinux
bind security update (RLSA-2022:8068) bind-libs-9.16.23-5.el9_1.x86_64.rpmLinux
bind security update (RLSA-2022:8068) bind-utils-9.16.23-5.el9_1.x86_64.rpmLinux
bind security update (RLSA-2022:8068) bind-chroot-9.16.23-5.el9_1.x86_64.rpmLinux
bind security update (RLSA-2022:8068) bind-license-9.16.23-5.el9_1.noarch.rpmLinux
bind security update (RLSA-2022:8068) python3-bind-9.16.23-5.el9_1.noarch.rpmLinux
bind security update (RLSA-2022:8068) bind-dnssec-doc-9.16.23-5.el9_1.noarch.rpmLinux
bind security update (RLSA-2022:8068) bind-dnssec-utils-9.16.23-5.el9_1.x86_64.rpmLinux
dhcp security and enhancement update (RLSA-2022:8385) dhcp-relay-4.4.2-17.b1.el9.x86_64.rpmLinux
dhcp security and enhancement update (RLSA-2022:8385) dhcp-client-4.4.2-17.b1.el9.x86_64.rpmLinux
dhcp security and enhancement update (RLSA-2022:8385) dhcp-common-4.4.2-17.b1.el9.noarch.rpmLinux
dhcp security and enhancement update (RLSA-2022:8385) dhcp-server-4.4.2-17.b1.el9.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) python3-bind-9.16.27-1.amzn2023.0.2.noarch.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-chroot-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-devel-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-dlz-filesystem-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-dlz-ldap-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-dlz-mysql-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-dlz-sqlite3-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-dnssec-doc-9.16.27-1.amzn2023.0.2.noarch.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-dnssec-utils-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-doc-9.16.27-1.amzn2023.0.2.noarch.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-libs-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-license-9.16.27-1.amzn2023.0.2.noarch.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-pkcs11-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-pkcs11-devel-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-pkcs11-libs-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-pkcs11-utils-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
bind Security Update (ALAS2023-2023-010) bind-utils-9.16.27-1.amzn2023.0.2.x86_64.rpmLinux
Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling) Vulnerability (CVE-2021-25220)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234