CVE-2014-8500

HIGH

Description

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

References

http://advisories.mageia.org/MGASA-2014-0524.html

http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html

http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.asc

http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676

http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html

http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.html

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.html

http://lists.opensuse.org/opensuse-updates/2015-07/msg00038.html

http://marc.info/?l=bugtraq&m=142180687100892&w=2

http://marc.info/?l=bugtraq&m=144000632319155&w=2

http://rhn.redhat.com/errata/RHSA-2016-0078.html

http://secunia.com/advisories/62064

http://secunia.com/advisories/62122

http://security.gentoo.org/glsa/glsa-201502-03.xml

http://securitytracker.com/id?1031311

http://ubuntu.com/usn/usn-2437-1

http://www.debian.org/security/2014/dsa-3094

http://www.kb.cert.org/vuls/id/264212

http://www.mandriva.com/security/advisories?name=MDVSA-2015:165

http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html

http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html

http://www.securityfocus.com/bid/71590

https://kb.isc.org/article/AA-01216/

https://security.netapp.com/advisory/ntap-20190730-0002/

https://support.apple.com/HT205219

Details

Source: MITRE

Published: 2014-12-11

Updated: 2017-01-03

Type: CWE-399

Risk Information

CVSS v2.0

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:isc:bind:9.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.0.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.1.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.1.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.1.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.4:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.5:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.6:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.7:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.8:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.2.9:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.4:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.5:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.3.6:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.4:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.4.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.4.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.4.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.4.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.5:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.5.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.5.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.5.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.5.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.6.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.6.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.6.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.6.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.4:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.5:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.6:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.7.7:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.4:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.5:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.8.6:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.1:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.2:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.3:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.4:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.5:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.9.6:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.10.0:*:*:*:*:*:*:*

cpe:2.3:a:isc:bind:9.10.1:*:*:*:*:*:*:*

Tenable Plugins

View all (44 total)

IDNameProductFamilySeverity
137170OracleVM 3.3 / 3.4 : bind (OVMSA-2020-0021)NessusOracleVM Local Security Checks
critical
124936EulerOS Virtualization 3.0.1.0 : bind (EulerOS-SA-2019-1433)NessusHuawei Local Security Checks
medium
99569OracleVM 3.3 / 3.4 : bind (OVMSA-2017-0066)NessusOracleVM Local Security Checks
critical
91739OracleVM 3.2 : bind (OVMSA-2016-0055)NessusOracleVM Local Security Checks
high
88479RHEL 6 : bind (RHSA-2016:0078)NessusRed Hat Local Security Checks
high
86066Mac OS X : OS X Server < 5.0.3 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
85146OracleVM 3.3 : bind (OVMSA-2015-0105)NessusOracleVM Local Security Checks
high
84816openSUSE Security Update : bind (openSUSE-2015-494)NessusSuSE Local Security Checks
high
83697SUSE SLES10 Security Update : bind (SUSE-SU-2015:0488-1)NessusSuSE Local Security Checks
high
83670SUSE SLED12 / SLES12 Security Update : bind (SUSE-SU-2015:0096-1)NessusSuSE Local Security Checks
high
82914Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : bind (SSA:2015-111-01)NessusSlackware Local Security Checks
high
82418Mandriva Linux Security Advisory : bind (MDVSA-2015:165)NessusMandriva Local Security Checks
high
82096Debian DLA-112-1 : bind9 security updateNessusDebian Local Security Checks
high
81608F5 Networks BIG-IP : BIND vulnerability (SOL15927)NessusF5 Networks Local Security Checks
high
81502AIX 5.3 TL 12 : bind9 (IV68997)NessusAIX Local Security Checks
high
81501AIX 7.1 TL 3 : bind9 (IV68996)NessusAIX Local Security Checks
high
81500AIX 7.1 TL 2 : bind9 (IV68995)NessusAIX Local Security Checks
high
81499AIX 6.1 TL 9 : bind9 (IV68994)NessusAIX Local Security Checks
high
81498AIX 6.1 TL 8 : bind9 (IV68993)NessusAIX Local Security Checks
high
81490ISC BIND 9.9.7.x < 9.9.7rc2 Multiple VulnerabilitiesNessusDNS
high
81487ISC BIND 9.10.2 < 9.10.2rc2 Multiple VulnerabilitiesNessusDNS
high
81226GLSA-201502-03 : BIND: Multiple VulnerabilitiesNessusGentoo Local Security Checks
high
80416Amazon Linux AMI : bind (ALAS-2015-465)NessusAmazon Linux Local Security Checks
high
80389SuSE 11.3 Security Update : bind (SAT Patch Number 10100)NessusSuSE Local Security Checks
high
80370Fedora 19 : bind-9.9.3-16.P2.fc19 (2014-16576)NessusFedora Local Security Checks
high
80369Fedora 21 : bind-9.9.6-5.P1.fc21 (2014-16557)NessusFedora Local Security Checks
high
80247OracleVM 3.3 : bind (OVMSA-2014-0084)NessusOracleVM Local Security Checks
high
80091Fedora 20 : bind-9.9.4-17.P2.fc20 (2014-16607)NessusFedora Local Security Checks
high
8602ISC BIND 9.0.x < 9.9.6-P1 'named' Delegation Handling DoSNessus Network MonitorDNS Servers
high
8569ISC BIND 9.10.x < 9.10.1-P1 Multiple DoSNessus Network MonitorDNS Servers
high
80020Scientific Linux Security Update : bind on SL5.x, SL6.x, SL7.x i386/x86_64 (20141212)NessusScientific Linux Local Security Checks
high
80019Scientific Linux Security Update : bind97 on SL5.x i386/x86_64 (20141212)NessusScientific Linux Local Security Checks
high
80013RHEL 5 : bind97 (RHSA-2014:1985)NessusRed Hat Local Security Checks
high
80012RHEL 5 / 6 / 7 : bind (RHSA-2014:1984)NessusRed Hat Local Security Checks
high
80003Oracle Linux 5 : bind97 (ELSA-2014-1985)NessusOracle Linux Local Security Checks
high
80002Oracle Linux 5 / 6 / 7 : bind (ELSA-2014-1984)NessusOracle Linux Local Security Checks
high
79983Mandriva Linux Security Advisory : bind (MDVSA-2014:238)NessusMandriva Local Security Checks
high
79957FreeBSD : bind -- denial of service vulnerability (ab3e98d9-8175-11e4-907d-d050992ecde8)NessusFreeBSD Local Security Checks
high
79881CentOS 5 : bind97 (CESA-2014:1985)NessusCentOS Local Security Checks
high
79880CentOS 5 / 6 / 7 : bind (CESA-2014:1984)NessusCentOS Local Security Checks
high
79866Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : bind (SSA:2014-344-01)NessusSlackware Local Security Checks
high
79861ISC BIND 9 Multiple DoS VulnerabilitiesNessusDNS
high
79854Ubuntu 10.04 LTS / 12.04 LTS / 14.04 LTS / 14.10 : bind9 vulnerability (USN-2437-1)NessusUbuntu Local Security Checks
high
79808Debian DSA-3094-1 : bind9 - security updateNessusDebian Local Security Checks
high