CVE-2014-8500
Last modified
CVE-2014-8500 is a vulnerability of currently unknown severity. ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.. EPSS estimates a 65.68% chance of exploitation in the next 30 days.
Description
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Isc | Bind | 9.0 |
| Isc | Bind | 9.0.1 |
| Isc | Bind | 9.1 |
| Isc | Bind | 9.1.1 |
| Isc | Bind | 9.1.2 |
| Isc | Bind | 9.1.3 |
| Isc | Bind | 9.2 |
| Isc | Bind | 9.2.0 |
| Isc | Bind | 9.2.1 |
| Isc | Bind | 9.2.2 |
| Isc | Bind | 9.2.3 |
| Isc | Bind | 9.2.4 |
| Isc | Bind | 9.2.5 |
| Isc | Bind | 9.2.6 |
| Isc | Bind | 9.2.7 |
| Isc | Bind | 9.2.8 |
| Isc | Bind | 9.2.9 |
| Isc | Bind | 9.3 |
| Isc | Bind | 9.3.0 |
| Isc | Bind | 9.3.1 |
| Isc | Bind | 9.3.2 |
| Isc | Bind | 9.3.3 |
| Isc | Bind | 9.3.4 |
| Isc | Bind | 9.3.5 |
| Isc | Bind | 9.3.6 |
| Isc | Bind | 9.4 |
| Isc | Bind | 9.4.0 |
| Isc | Bind | 9.4.1 |
| Isc | Bind | 9.4.2 |
| Isc | Bind | 9.4.3 |
| Isc | Bind | 9.5 |
| Isc | Bind | 9.5.0 |
| Isc | Bind | 9.5.1 |
| Isc | Bind | 9.5.2 |
| Isc | Bind | 9.5.3 |
| Isc | Bind | 9.6.0 |
| Isc | Bind | 9.6.1 |
| Isc | Bind | 9.6.2 |
| Isc | Bind | 9.6.3 |
| Isc | Bind | 9.7.0 |
| Isc | Bind | 9.7.1 |
| Isc | Bind | 9.7.2 |
| Isc | Bind | 9.7.3 |
| Isc | Bind | 9.7.4 |
| Isc | Bind | 9.7.5 |
| Isc | Bind | 9.7.6 |
| Isc | Bind | 9.7.7 |
| Isc | Bind | 9.8.0 |
| Isc | Bind | 9.8.1 |
| Isc | Bind | 9.8.2 |
Showing 50 of 63 affected configurations. See NVD for the full list.
References
- http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.htmlVendor Advisory
- http://ubuntu.com/usn/usn-2437-1Patch, Vendor Advisory
- http://www.debian.org/security/2014/dsa-3094Vendor Advisory
- http://www.kb.cert.org/vuls/id/264212Third Party Advisory, US Government Resource
- https://kb.isc.org/article/AA-01216/Vendor Advisory
- http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.htmlVendor Advisory
- http://ubuntu.com/usn/usn-2437-1Patch, Vendor Advisory
- http://www.debian.org/security/2014/dsa-3094Vendor Advisory
- http://www.kb.cert.org/vuls/id/264212Third Party Advisory, US Government Resource
- https://kb.isc.org/article/AA-01216/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-8500?
How severe is CVE-2014-8500?
How do I fix CVE-2014-8500?
Are you affected by CVE-2014-8500?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
