CVE-2014-0591
published 2014-01-14CVE-2014-0591: The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before…
PriorityP425low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
31.67%
98.1th percentile
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.9.5.dfsg-2 (bookworm) | bind9 1:9.9.5.dfsg-2 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-2 | 1:9.9.5.dfsg-2 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-2 | 1:9.9.5.dfsg-2 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-2 | 1:9.9.5.dfsg-2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target process is 'named' (BIND daemon); a crash (INSIST assertion failure in name.c) indicates exploitation attempt against an authoritative nameserver serving NSEC3-signed zones. ↗
- →Recursive-only BIND servers are NOT vulnerable; detection/monitoring should focus exclusively on authoritative nameservers configured with at least one NSEC3-signed zone. ↗
- →The vulnerable code path is query_findclosestnsec3() in query.c; crash stack traces referencing this function or name.c INSIST failures on an authoritative BIND server are strong indicators of exploitation. ↗
- ·Only BIND versions 9.6.0 and higher are affected (NSEC3 support was introduced in 9.6.0); servers running older versions are not vulnerable. ↗
- ·The vulnerability is only exploitable if the authoritative nameserver is actively serving at least one NSEC3-signed zone; NSEC3 is not automatically enabled by default. ↗
- ·The vulnerability is more reliably triggered on systems with newer glibc implementations; BIND on RHEL 5 (with older glibc) was assessed as not affected in practice. ↗
- ·No workaround is available; the only mitigation is patching to fixed versions (9.8.6-P2, 9.9.4-P2, or 9.6-ESV-R10-P2). ↗
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-14:04.bind: BIND remote denial of service vulnerability
bsd_advisories·2014-01-14·CVSS 2.6
CVE-2014-0591 [LOW] FreeBSD-SA-14:04.bind: BIND remote denial of service vulnerability
FreeBSD-SA-14:04.bind Security Advisory
The FreeBSD Project
Topic: BIND remote denial of service vulnerability
Category: contrib
Module: bind
Announced: 2014-01-14
Credits: ISC
Affects: FreeBSD 8.x and FreeBSD 9.x
Corrected: 2014-01-14 19:38:37 UTC (stable/9, 9.2-STABLE)
2014-01-14 19:42:28 UTC (releng/9.2, 9.2-RELEASE-p3)
2014-01-14 19:42:28 UTC (releng/9.1, 9.1-RELEASE-p10)
2014-01-14 19:38:37 UTC (stable/8, 8.4-STABLE)
2014-01-14 19:42:28 UTC (releng/8.4, 8.4-RELEASE-p7)
2014-01-14 19:42:28 UTC (releng/8.3, 8.3-RELEASE-p14)
CVE Name: CVE-2014-0591
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (
Red Hat
bind: named crash when handling malformed NSEC3-signed zones
vendor_redhat·2014-01-13·CVSS 2.6
CVE-2014-0591 [LOW] bind: named crash when handling malformed NSEC3-signed zones
bind: named crash when handling malformed NSEC3-signed zones
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
A denial of service flaw was found in the way BIND handled queries for NSEC3-signed zones. A remote attacker could use this flaw against an authoritative name server that served NCES3-signed zones by sending a specially crafted query, which, when processed, would cause named to crash.
Statement: This issue does not affect the version of bind and bind97 as shipped with Red Hat Enterpr
Ubuntu
Bind vulnerability
vendor_ubuntu·2014-01-13
CVE-2014-0591 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Jared Mauch discovered that Bind incorrectly handled certain queries for
NSEC3-signed zones. A remote attacker could use this flaw with a specially
crafted query to cause Bind to stop responding, resulting in a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-0591: bind9 - The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, an...
vendor_debian·2014·CVSS 2.6
CVE-2014-0591 [LOW] CVE-2014-0591: bind9 - The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, an...
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
Scope: local
bookworm: resolved (fixed in 1:9.9.5.dfsg-2)
bullseye: resolved (fixed in 1:9.9.5.dfsg-2)
forky: resolved (fixed in 1:9.9.5.dfsg-2)
sid: resolved (fixed in 1:9.9.5.dfsg-2)
trixie: resolved (fixed in 1:9.9.5.dfsg-2)
GHSA
GHSA-c7r2-3x52-rjcm: The query_findclosestnsec3 function in query
ghsa_unreviewed·2022-05-14
CVE-2014-0591 [LOW] CWE-119 GHSA-c7r2-3x52-rjcm: The query_findclosestnsec3 function in query
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
OSV
CVE-2014-0591: The query_findclosestnsec3 function in query
osv·2014-01-14·CVSS 2.6
CVE-2014-0591 [LOW] CVE-2014-0591: The query_findclosestnsec3 function in query
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0591 bind: named crash when handling malformed NSEC3-signed zones [fedora-all]
bugzilla·2014-01-13·CVSS 2.6
CVE-2014-0591 [LOW] CVE-2014-0591 bind: named crash when handling malformed NSEC3-signed zones [fedora-all]
CVE-2014-0591 bind: named crash when handling malformed NSEC3-signed zones [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2014-0591 bind: named crash when handling malformed NSEC3-signed zones
bugzilla·2014-01-11·CVSS 2.6
CVE-2014-0591 [LOW] CVE-2014-0591 bind: named crash when handling malformed NSEC3-signed zones
CVE-2014-0591 bind: named crash when handling malformed NSEC3-signed zones
It was reported that a defect in how BIND handled queries for NSEC3-signed
zones could cause a crash of the named daemon with an "INSIST" failure when
processing queries that possessed certain properties.
A remote attacker could exploit this defect by constructing a
carefully-crafted query against an authoritative nameserver that served
NSEC3-signed zones.
Note that this flaw affects BIND versions 9.6.0 and higher (NSEC3 was
introduced in BIND 9.6.0 but is not automatically enabled). Authoritative
nameservers that are serving at least one NSEC3-signed zone are vulnerable.
Authoritative nameservers that are NOT serving at least one NSEC3-signed
zone are not vulnerable, nor are recursive-only servers. Servers runni
http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.htmlhttp://linux.oracle.com/errata/ELSA-2014-1244http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00016.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00019.htmlhttp://marc.info/?l=bugtraq&m=138995561732658&w=2http://osvdb.org/101973http://rhn.redhat.com/errata/RHSA-2014-0043.htmlhttp://secunia.com/advisories/56425http://secunia.com/advisories/56427http://secunia.com/advisories/56442http://secunia.com/advisories/56493http://secunia.com/advisories/56522http://secunia.com/advisories/56574http://secunia.com/advisories/56871http://secunia.com/advisories/61117http://secunia.com/advisories/61199http://secunia.com/advisories/61343http://www.debian.org/security/2014/dsa-3023http://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.aschttp://www.mandriva.com/security/advisories?name=MDVSA-2014:002http://www.securityfocus.com/bid/64801http://www.securitytracker.com/id/1029589http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.518391http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.524465http://www.ubuntu.com/usn/USN-2081-1https://bugzilla.redhat.com/show_bug.cgi?id=1051717https://kb.isc.org/article/AA-01078https://kb.isc.org/article/AA-01085https://support.apple.com/kb/HT6536http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.htmlhttp://linux.oracle.com/errata/ELSA-2014-1244http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00016.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00019.htmlhttp://marc.info/?l=bugtraq&m=138995561732658&w=2http://osvdb.org/101973http://rhn.redhat.com/errata/RHSA-2014-0043.htmlhttp://secunia.com/advisories/56425http://secunia.com/advisories/56427http://secunia.com/advisories/56442http://secunia.com/advisories/56493http://secunia.com/advisories/56522http://secunia.com/advisories/56574http://secunia.com/advisories/56871http://secunia.com/advisories/61117http://secunia.com/advisories/61199http://secunia.com/advisories/61343http://www.debian.org/security/2014/dsa-3023http://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.aschttp://www.mandriva.com/security/advisories?name=MDVSA-2014:002http://www.securityfocus.com/bid/64801http://www.securitytracker.com/id/1029589http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.518391http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.524465http://www.ubuntu.com/usn/USN-2081-1https://bugzilla.redhat.com/show_bug.cgi?id=1051717https://kb.isc.org/article/AA-01078https://kb.isc.org/article/AA-01085https://support.apple.com/kb/HT6536
2014-01-14
Published