CVE-2014-3214
published 2014-05-09CVE-2014-3214: The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
17.26%
96.9th percentile
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rqc-hcfp-rmjx: The prefetch implementation in named in ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2014-3214 [MEDIUM] CWE-20 GHSA-9rqc-hcfp-rmjx: The prefetch implementation in named in ISC BIND 9
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
Red Hat
bind: assertion failure when using prefetch
vendor_redhat·2014-05-08·CVSS 5.0
CVE-2014-3214 [MEDIUM] bind: assertion failure when using prefetch
bind: assertion failure when using prefetch
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
Statement: Not vulnerable. This issue did not affect the versions of bind or bind97 as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-3214: bind9 - The prefetch implementation in named in ISC BIND 9.10.0, when a recursive namese...
vendor_debian·2014·CVSS 5.0
CVE-2014-3214 [MEDIUM] CVE-2014-3214: bind9 - The prefetch implementation in named in ISC BIND 9.10.0, when a recursive namese...
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2014-05-09
Published