CVE-2014-8500
published 2014-12-11CVE-2014-8500: ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a…
PriorityP350high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
65.68%
99.2th percentile
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_server_v5.0.3 | — | — |
| debian | bind9 | < bind9 1:9.9.5.dfsg-7 (bookworm) | bind9 1:9.9.5.dfsg-7 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →All recursive BIND DNS resolvers are vulnerable; authoritative servers are only vulnerable if an attacker can control a delegation traversed by the authoritative server. ↗
- →Attack vector is DNS delegation chaining — attacker causes named to issue unlimited queries by serving a maliciously-constructed zone or acting as a rogue DNS server with excessive/infinite referrals. ↗
- →Monitor named (BIND) process for abnormal memory consumption or crashes, which are the observable symptoms of a successful exploitation attempt. ↗
- →Attack is triggered by causing specific DNS queries to be sent to a nameserver that then follows a maliciously-constructed delegation chain; monitor for named(8) crashes. ↗
- ·Affected BIND versions are 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1; fixed in 9.9.6-P1 and 9.10.1-P1. ↗
- ·No workaround is available; hosts not running named(8) are not vulnerable. Mitigation requires upgrading to a patched BIND release. ↗
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-14:29.bind: BIND remote denial of service vulnerability
bsd_advisories·2014-12-10·CVSS 7.8
CVE-2014-8500 [HIGH] FreeBSD-SA-14:29.bind: BIND remote denial of service vulnerability
FreeBSD-SA-14:29.bind Security Advisory
The FreeBSD Project
Topic: BIND remote denial of service vulnerability
Category: contrib
Module: bind
Announced: 2014-12-10
Credits: ISC
Affects: FreeBSD 8.4, 9.1, 9.2 and 9.3.
Corrected: 2014-12-10 08:31:41 UTC (stable/9, 9.3-STABLE)
2014-12-10 08:36:40 UTC (releng/9.3, 9.3-RELEASE-p6)
2014-12-10 08:36:40 UTC (releng/9.2, 9.2-RELEASE-p16)
2014-12-10 08:36:40 UTC (releng/9.1, 9.1-RELEASE-p23)
2014-12-10 08:31:41 UTC (stable/8, 8.4-STABLE)
2014-12-10 08:36:40 UTC (releng/8.4, 8.4-RELEASE-p20)
CVE Name: CVE-2014-8500
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name Syst
Ubuntu
Bind vulnerability
vendor_ubuntu·2014-12-09
CVE-2014-8500 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Florian Maury discovered that Bind incorrectly handled delegation. A remote
attacker could possibly use this issue to cause Bind to consume resources
and crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: delegation handling denial of service
vendor_redhat·2014-12-08·CVSS 7.8
CVE-2014-8500 [HIGH] CWE-400 bind: delegation handling denial of service
bind: delegation handling denial of service
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
A denial of service flaw was found in the way BIND followed DNS delegations. A remote attacker could use a specially crafted zone containing a large number of referrals which, when looked up and processed, would cause named to use excessive amounts of memory or crash.
Debian
CVE-2014-8500: bind9 - ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 doe...
vendor_debian·2014·CVSS 7.8
CVE-2014-8500 [HIGH] CVE-2014-8500: bind9 - ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 doe...
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
Scope: local
bookworm: resolved (fixed in 1:9.9.5.dfsg-7)
bullseye: resolved (fixed in 1:9.9.5.dfsg-7)
forky: resolved (fixed in 1:9.9.5.dfsg-7)
sid: resolved (fixed in 1:9.9.5.dfsg-7)
trixie: resolved (fixed in 1:9.9.5.dfsg-7)
Apple
CVE-2014-8500: OS X Server v5.0.3
vendor_apple·CVSS 7.8
CVE-2014-8500 [HIGH] CVE-2014-8500: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2014-8500
Component: CVE-2014-8500
GHSA
GHSA-qcv9-4m2r-585w: ISC BIND 9
ghsa_unreviewed·2022-05-17
CVE-2014-8500 [HIGH] GHSA-qcv9-4m2r-585w: ISC BIND 9
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
OSV
CVE-2014-8500: ISC BIND 9
osv·2014-12-11·CVSS 7.8
CVE-2014-8500 [HIGH] CVE-2014-8500: ISC BIND 9
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8500 bind: delegation handling denial of service
bugzilla·2014-12-08·CVSS 7.8
CVE-2014-8500 [HIGH] CVE-2014-8500 bind: delegation handling denial of service
CVE-2014-8500 bind: delegation handling denial of service
The BIND 9.9.6-P1 and 9.10.1-P1 release fix the following flaw:
""
By making use of maliciously-constructed zones or a rogue server, an attacker can exploit an oversight in the code BIND 9 uses to follow delegations in the Domain Name Service, causing BIND to issue unlimited queries in an attempt to follow the delegation. This can lead to resource exhaustion and denial of service (up to and including termination of the named server process.)
All recursive resolvers are affected. Authoritative servers can be affected if an attacker can control a delegation traversed by the authoritative server in servicing the zone.
""
It is reported that versions 9.0.x to 9.8.x, 9.9.0 to 9.9.6, and 9.10.0 to 9.10.1 are affected.
External Refere
Bugzilla
CVE-2014-8500 bind: delegation handling denial of service [fedora-all]
bugzilla·2014-12-08·CVSS 7.8
CVE-2014-8500 [HIGH] CVE-2014-8500 bind: delegation handling denial of service [fedora-all]
CVE-2014-8500 bind: delegation handling denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://advisories.mageia.org/MGASA-2014-0524.htmlhttp://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.htmlhttp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.aschttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00038.htmlhttp://marc.info/?l=bugtraq&m=142180687100892&w=2http://marc.info/?l=bugtraq&m=144000632319155&w=2http://rhn.redhat.com/errata/RHSA-2016-0078.htmlhttp://secunia.com/advisories/62064http://secunia.com/advisories/62122http://security.gentoo.org/glsa/glsa-201502-03.xmlhttp://securitytracker.com/id?1031311http://ubuntu.com/usn/usn-2437-1http://www.debian.org/security/2014/dsa-3094http://www.kb.cert.org/vuls/id/264212http://www.mandriva.com/security/advisories?name=MDVSA-2015:165http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/71590https://kb.isc.org/article/AA-01216/https://security.netapp.com/advisory/ntap-20190730-0002/https://support.apple.com/HT205219http://advisories.mageia.org/MGASA-2014-0524.htmlhttp://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.htmlhttp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.aschttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00038.htmlhttp://marc.info/?l=bugtraq&m=142180687100892&w=2http://marc.info/?l=bugtraq&m=144000632319155&w=2http://rhn.redhat.com/errata/RHSA-2016-0078.htmlhttp://secunia.com/advisories/62064http://secunia.com/advisories/62122http://security.gentoo.org/glsa/glsa-201502-03.xmlhttp://securitytracker.com/id?1031311http://ubuntu.com/usn/usn-2437-1http://www.debian.org/security/2014/dsa-3094http://www.kb.cert.org/vuls/id/264212http://www.mandriva.com/security/advisories?name=MDVSA-2015:165http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/71590https://kb.isc.org/article/AA-01216/https://security.netapp.com/advisory/ntap-20190730-0002/https://support.apple.com/HT205219
2014-12-11
Published