cbcvebase.
CVE-2014-8500
published 2014-12-11

CVE-2014-8500: ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a…

PriorityP350high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
65.68%
99.2th percentile
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
appleos_x_server_v5.0.3
debianbind9< bind9 1:9.9.5.dfsg-7 (bookworm)bind9 1:9.9.5.dfsg-7 (bookworm)
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind

Detection & IOCsextracted from sources · hover to see the quote

  • All recursive BIND DNS resolvers are vulnerable; authoritative servers are only vulnerable if an attacker can control a delegation traversed by the authoritative server.
  • Attack vector is DNS delegation chaining — attacker causes named to issue unlimited queries by serving a maliciously-constructed zone or acting as a rogue DNS server with excessive/infinite referrals.
  • Monitor named (BIND) process for abnormal memory consumption or crashes, which are the observable symptoms of a successful exploitation attempt.
  • Attack is triggered by causing specific DNS queries to be sent to a nameserver that then follows a maliciously-constructed delegation chain; monitor for named(8) crashes.
  • ·Affected BIND versions are 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1; fixed in 9.9.6-P1 and 9.10.1-P1.
  • ·No workaround is available; hosts not running named(8) are not vulnerable. Mitigation requires upgrading to a patched BIND release.

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.