CVE-2014-8680
published 2014-12-11CVE-2014-8680: The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors…
PriorityP428medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
8.99%
94.9th percentile
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: flaws in GeoIP leading to a denial of service
vendor_redhat·2014-12-08·CVSS 5.4
CVE-2014-8680 [MEDIUM] CWE-617 bind: flaws in GeoIP leading to a denial of service
bind: flaws in GeoIP leading to a denial of service
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
Statement: Not vulnerable. This issue did not affect the versions of bind or bind97 as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-8680: bind9 - The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attacker...
vendor_debian·2014·CVSS 5.4
CVE-2014-8680 [MEDIUM] CVE-2014-8680: bind9 - The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attacker...
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-29cv-f9xj-9653: The GeoIP functionality in ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2014-8680 [MEDIUM] CWE-20 GHSA-29cv-f9xj-9653: The GeoIP functionality in ISC BIND 9
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
No detection rules found.
No public exploits indexed.
2014-12-11
Published