ALPINE-CVE-2020-8616

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 19 May 2020, 14:15
Last modified:03 Dec 2025, 22:47

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.6 HIGH
3.1 (osv_alpine)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 May 2020, 14:15
Published
Vulnerability first disclosed
03 Dec 2025, 22:47
Last Modified
Vulnerability information updated

Description

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.

CVSS Metrics

  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected Systems

  • alpinebind

    < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0 | < 9.14.12-r0

References (1)