ISC BIND
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*
- >= 9.20.0, <= 9.20.22
- >= 9.21.0, <= 9.21.21
- >= 9.20.9-S1, <= 9.20.22-S1
A heap use-after-free vulnerability has been identified in the DNS-over-HTTPS implementation of BIND 9. This vulnerability affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. The vulnerability allows crafted HTTP/2 traffic sent to a DNS-over-HTTPS endpoint to trigger memory corruption, potentially leading to arbitrary code execution.
Exploitation of this vulnerability can cause memory corruption, with the potential for arbitrary code execution.
Users can upgrade to BIND 9.20.23, 9.21.22, or 9.20.23-S1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.