// For flags

CVE-2014-0591

bind: named crash when handling malformed NSEC3-signed zones

Severity Score

2.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

La función query_findclosestnsec3 en query.c de ISC BIND 9.6, 9.7, y 9.8 anterior a la versión 9.8.6-P2 y 9.9 anterior a 9.9.4-P2, y 9.6-ESV anterior a la versión 9.6-ESV-R10-02, permite a atacantes remotos provocar una denegación de servicio (salida del demonio y fallo de aserción INSIST) a través de una consulta hacia un servidor de nombres autoritativo que use la característica de firma NSEC3.

A denial of service flaw was found in the way BIND handled queries for NSEC3-signed zones. A remote attacker could use this flaw against an authoritative name server that served NCES3-signed zones by sending a specially crafted query, which, when processed, would cause named to crash.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-27 CVE Reserved
  • 2014-01-13 CVE Published
  • 2023-08-26 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (33)
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r5_p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r6_b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r6_rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r6_rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r7_p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r7_p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6
Search vendor "Isc" for product "Bind" and version "9.6"
r9_p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.0
Search vendor "Isc" for product "Bind" and version "9.6.0"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.0
Search vendor "Isc" for product "Bind" and version "9.6.0"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.0
Search vendor "Isc" for product "Bind" and version "9.6.0"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.0
Search vendor "Isc" for product "Bind" and version "9.6.0"
rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.1
Search vendor "Isc" for product "Bind" and version "9.6.1"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.1
Search vendor "Isc" for product "Bind" and version "9.6.1"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.1
Search vendor "Isc" for product "Bind" and version "9.6.1"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.1
Search vendor "Isc" for product "Bind" and version "9.6.1"
p3
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.1
Search vendor "Isc" for product "Bind" and version "9.6.1"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.2
Search vendor "Isc" for product "Bind" and version "9.6.2"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.2
Search vendor "Isc" for product "Bind" and version "9.6.2"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.3
Search vendor "Isc" for product "Bind" and version "9.6.3"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.6.3
Search vendor "Isc" for product "Bind" and version "9.6.3"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.0
Search vendor "Isc" for product "Bind" and version "9.7.0"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.0
Search vendor "Isc" for product "Bind" and version "9.7.0"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.0
Search vendor "Isc" for product "Bind" and version "9.7.0"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.0
Search vendor "Isc" for product "Bind" and version "9.7.0"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.0
Search vendor "Isc" for product "Bind" and version "9.7.0"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.0
Search vendor "Isc" for product "Bind" and version "9.7.0"
rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.1
Search vendor "Isc" for product "Bind" and version "9.7.1"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.1
Search vendor "Isc" for product "Bind" and version "9.7.1"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.1
Search vendor "Isc" for product "Bind" and version "9.7.1"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.1
Search vendor "Isc" for product "Bind" and version "9.7.1"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.2
Search vendor "Isc" for product "Bind" and version "9.7.2"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.2
Search vendor "Isc" for product "Bind" and version "9.7.2"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.2
Search vendor "Isc" for product "Bind" and version "9.7.2"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.2
Search vendor "Isc" for product "Bind" and version "9.7.2"
p3
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.2
Search vendor "Isc" for product "Bind" and version "9.7.2"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.3
Search vendor "Isc" for product "Bind" and version "9.7.3"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.3
Search vendor "Isc" for product "Bind" and version "9.7.3"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.3
Search vendor "Isc" for product "Bind" and version "9.7.3"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.3
Search vendor "Isc" for product "Bind" and version "9.7.3"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.4
Search vendor "Isc" for product "Bind" and version "9.7.4"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.4
Search vendor "Isc" for product "Bind" and version "9.7.4"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.4
Search vendor "Isc" for product "Bind" and version "9.7.4"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.4
Search vendor "Isc" for product "Bind" and version "9.7.4"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.5
Search vendor "Isc" for product "Bind" and version "9.7.5"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.5
Search vendor "Isc" for product "Bind" and version "9.7.5"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.5
Search vendor "Isc" for product "Bind" and version "9.7.5"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.5
Search vendor "Isc" for product "Bind" and version "9.7.5"
rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.6
Search vendor "Isc" for product "Bind" and version "9.7.6"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.6
Search vendor "Isc" for product "Bind" and version "9.7.6"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.6
Search vendor "Isc" for product "Bind" and version "9.7.6"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.7.7
Search vendor "Isc" for product "Bind" and version "9.7.7"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
a1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
p4
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.0
Search vendor "Isc" for product "Bind" and version "9.8.0"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.1
Search vendor "Isc" for product "Bind" and version "9.8.1"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.1
Search vendor "Isc" for product "Bind" and version "9.8.1"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.1
Search vendor "Isc" for product "Bind" and version "9.8.1"
b2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.1
Search vendor "Isc" for product "Bind" and version "9.8.1"
b3
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.1
Search vendor "Isc" for product "Bind" and version "9.8.1"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.1
Search vendor "Isc" for product "Bind" and version "9.8.1"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.2
Search vendor "Isc" for product "Bind" and version "9.8.2"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.2
Search vendor "Isc" for product "Bind" and version "9.8.2"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.2
Search vendor "Isc" for product "Bind" and version "9.8.2"
rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.3
Search vendor "Isc" for product "Bind" and version "9.8.3"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.3
Search vendor "Isc" for product "Bind" and version "9.8.3"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.3
Search vendor "Isc" for product "Bind" and version "9.8.3"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.4
Search vendor "Isc" for product "Bind" and version "9.8.4"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
b2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
p2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.5
Search vendor "Isc" for product "Bind" and version "9.8.5"
rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.6
Search vendor "Isc" for product "Bind" and version "9.8.6"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.6
Search vendor "Isc" for product "Bind" and version "9.8.6"
b1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.6
Search vendor "Isc" for product "Bind" and version "9.8.6"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.6
Search vendor "Isc" for product "Bind" and version "9.8.6"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.8.6
Search vendor "Isc" for product "Bind" and version "9.8.6"
rc2
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.9.4
Search vendor "Isc" for product "Bind" and version "9.9.4"
-
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.9.4
Search vendor "Isc" for product "Bind" and version "9.9.4"
p1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.9.4
Search vendor "Isc" for product "Bind" and version "9.9.4"
rc1
Affected
Isc
Search vendor "Isc"
Bind
Search vendor "Isc" for product "Bind"
9.9.4
Search vendor "Isc" for product "Bind" and version "9.9.4"
rc2
Affected