A vulnerability in the BIND DNS server that does not preclude remote code execution
Corrective updates for the stable branches of the DNS server BIND 9.11.28 and 9.16.12, as well as the experimental branch 9.17.10 currently in development, have been released. The new versions fix a vulnerability (CVE-2020-8625) that leads to a buffer overflow and could potentially allow remote code execution by an attacker. No evidence of working exploits has been found so far. The issue is caused by a bug in the implementation of the SPNEGO (Simple and Protected GSSAPI […
