CVE-2014-3859
published 2014-06-13CVE-2014-3859: libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.98%
93.7th percentile
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: assertion failure during EDNS option processing
vendor_redhat·2014-06-11·CVSS 5.0
CVE-2014-3859 [MEDIUM] bind: assertion failure during EDNS option processing
bind: assertion failure during EDNS option processing
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.
Statement: Not vulnerable. This issue did not affect the versions of bind or bind97 as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-3859: bind9 - libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which...
vendor_debian·2014·CVSS 5.0
CVE-2014-3859 [MEDIUM] CVE-2014-3859: bind9 - libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which...
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-fhwv-x286-vrwh: libdns in ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2014-3859 [MEDIUM] CWE-20 GHSA-fhwv-x286-vrwh: libdns in ISC BIND 9
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/58946http://www.securityfocus.com/bid/68193http://www.securitytracker.com/id/1030414https://kb.isc.org/article/AA-01166/https://kb.isc.org/article/AA-01171/http://secunia.com/advisories/58946http://www.securityfocus.com/bid/68193http://www.securitytracker.com/id/1030414https://kb.isc.org/article/AA-01166/https://kb.isc.org/article/AA-01171/
2014-06-13
Published