CVE-2021-25215 (CNNVD-202104-2109)
中文标题:
ISC BIND 安全漏洞
英文标题:
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
漏洞描述
中文描述:
ISC BIND是美国ISC公司的一套实现了DNS协议的开源软件。 ISC BIND 存在安全漏洞,该漏洞源于回答DNAME的查询时,断言检查可能会失败 需要处理DNAME才能解决的记录。
英文描述:
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| ISC | BIND9 | Open Source Branches 9.0 through 9.11 9.0.0 through versions before 9.11.30 | - | - |
cpe:2.3:a:isc:bind9:open_source_branches_9.0_through_9.11_9.0.0_through_versions_before_9.11.30:*:*:*:*:*:*:*
|
| ISC | BIND9 | Open Source Branches 9.12 through 9.16 9.12.0 through versions before 9.16.14 | - | - |
cpe:2.3:a:isc:bind9:open_source_branches_9.12_through_9.16_9.12.0_through_versions_before_9.16.14:*:*:*:*:*:*:*
|
| ISC | BIND9 | Supported Preview Branches 9.9-S through 9.11-S 9.9.3-S1 through versions before 9.11.30-S1 | - | - |
cpe:2.3:a:isc:bind9:supported_preview_branches_9.9-s_through_9.11-s_9.9.3-s1_through_versions_before_9.11.30-s1:*:*:*:*:*:*:*
|
| ISC | BIND9 | Supported Preview Branch 9.16-S 9.16.8-S1 through versions before 9.16.14-S1 | - | - |
cpe:2.3:a:isc:bind9:supported_preview_branch_9.16-s_9.16.8-s1_through_versions_before_9.16.14-s1:*:*:*:*:*:*:*
|
| ISC | BIND9 | Development Branch 9.17 9.17.0 through versiosn before 9.17.12 | - | - |
cpe:2.3:a:isc:bind9:development_branch_9.17_9.17.0_through_versiosn_before_9.17.12:*:*:*:*:*:*:*
|
| debian | debian_linux | 9.0 | - | - |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
| debian | debian_linux | 10.0 | - | - |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
| isc | bind | * | - | - |
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
|
| isc | bind | 9.9.3 | - | - |
cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.9.12 | - | - |
cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.9.13 | - | - |
cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.10.5 | - | - |
cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.10.7 | - | - |
cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.3 | - | - |
cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.5 | - | - |
cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.6 | - | - |
cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.7 | - | - |
cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.8 | - | - |
cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.12 | - | - |
cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.21 | - | - |
cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.27 | - | - |
cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.11.29 | - | - |
cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.16.8 | - | - |
cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.16.11 | - | - |
cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:*
|
| isc | bind | 9.16.13 | - | - |
cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:*
|
| fedoraproject | fedora | 33 | - | - |
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 34 | - | - |
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
|
| netapp | active_iq_unified_manager | - | - | - |
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
|
| netapp | cloud_backup | - | - | - |
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
|
| netapp | h300s_firmware | - | - | - |
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h500s_firmware | - | - | - |
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h700s_firmware | - | - | - |
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h300e_firmware | - | - | - |
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
|
| netapp | h500e_firmware | - | - | - |
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
|
| netapp | h700e_firmware | - | - | - |
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
|
| netapp | h410s_firmware | - | - | - |
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
|
| netapp | a250_firmware | - | - | - |
cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*
|
| netapp | 500f_firmware | - | - | - |
cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*
|
| oracle | tekelec_platform_distribution | * | - | - |
cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*
|
| siemens | sinec_infrastructure_network_services | * | - | - |
cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-25215 |
2025-11-11 15:20:51 | 2025-11-11 07:36:43 |
| NVD | nvd_CVE-2021-25215 |
2025-11-11 14:57:36 | 2025-11-11 07:45:03 |
| CNNVD | cnnvd_CNNVD-202104-2109 |
2025-11-11 15:10:37 | 2025-11-11 07:56:42 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202104-2109
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 5 -> 40
- data_sources: ['cve'] -> ['cve', 'nvd']