CVE Vulnerabilities

CVE-2014-8500

Published: Dec 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

Affected Software

NameVendorStart VersionEnd Version
BindIsc9.0 (including)9.0 (including)
BindIsc9.0.1 (including)9.0.1 (including)
BindIsc9.1 (including)9.1 (including)
BindIsc9.1.1 (including)9.1.1 (including)
BindIsc9.1.2 (including)9.1.2 (including)
BindIsc9.1.3 (including)9.1.3 (including)
BindIsc9.2 (including)9.2 (including)
BindIsc9.2.0 (including)9.2.0 (including)
BindIsc9.2.1 (including)9.2.1 (including)
BindIsc9.2.2 (including)9.2.2 (including)
BindIsc9.2.3 (including)9.2.3 (including)
BindIsc9.2.4 (including)9.2.4 (including)
BindIsc9.2.5 (including)9.2.5 (including)
BindIsc9.2.6 (including)9.2.6 (including)
BindIsc9.2.7 (including)9.2.7 (including)
BindIsc9.2.8 (including)9.2.8 (including)
BindIsc9.2.9 (including)9.2.9 (including)
BindIsc9.3 (including)9.3 (including)
BindIsc9.3.0 (including)9.3.0 (including)
BindIsc9.3.1 (including)9.3.1 (including)
BindIsc9.3.2 (including)9.3.2 (including)
BindIsc9.3.3 (including)9.3.3 (including)
BindIsc9.3.4 (including)9.3.4 (including)
BindIsc9.3.5 (including)9.3.5 (including)
BindIsc9.3.6 (including)9.3.6 (including)
BindIsc9.4 (including)9.4 (including)
BindIsc9.4.0 (including)9.4.0 (including)
BindIsc9.4.1 (including)9.4.1 (including)
BindIsc9.4.2 (including)9.4.2 (including)
BindIsc9.4.3 (including)9.4.3 (including)
BindIsc9.5 (including)9.5 (including)
BindIsc9.5.0 (including)9.5.0 (including)
BindIsc9.5.1 (including)9.5.1 (including)
BindIsc9.5.2 (including)9.5.2 (including)
BindIsc9.5.3 (including)9.5.3 (including)
BindIsc9.6.0 (including)9.6.0 (including)
BindIsc9.6.1 (including)9.6.1 (including)
BindIsc9.6.2 (including)9.6.2 (including)
BindIsc9.6.3 (including)9.6.3 (including)
BindIsc9.7.0 (including)9.7.0 (including)
BindIsc9.7.1 (including)9.7.1 (including)
BindIsc9.7.2 (including)9.7.2 (including)
BindIsc9.7.3 (including)9.7.3 (including)
BindIsc9.7.4 (including)9.7.4 (including)
BindIsc9.7.5 (including)9.7.5 (including)
BindIsc9.7.6 (including)9.7.6 (including)
BindIsc9.7.7 (including)9.7.7 (including)
BindIsc9.8.0 (including)9.8.0 (including)
BindIsc9.8.1 (including)9.8.1 (including)
BindIsc9.8.2 (including)9.8.2 (including)
BindIsc9.8.3 (including)9.8.3 (including)
BindIsc9.8.4 (including)9.8.4 (including)
BindIsc9.8.5 (including)9.8.5 (including)
BindIsc9.8.6 (including)9.8.6 (including)
BindIsc9.9.0 (including)9.9.0 (including)
BindIsc9.9.1 (including)9.9.1 (including)
BindIsc9.9.2 (including)9.9.2 (including)
BindIsc9.9.3 (including)9.9.3 (including)
BindIsc9.9.4 (including)9.9.4 (including)
BindIsc9.9.5 (including)9.9.5 (including)
BindIsc9.9.6 (including)9.9.6 (including)
BindIsc9.10.0 (including)9.10.0 (including)
BindIsc9.10.1 (including)9.10.1 (including)
Red Hat Enterprise Linux 5RedHatbind-30:9.3.6-25.P1.el5_11.2*
Red Hat Enterprise Linux 5RedHatbind97-32:9.7.0-21.P2.el5_11.1*
Red Hat Enterprise Linux 6RedHatbind-32:9.8.2-0.30.rc1.el6_6.1*
Red Hat Enterprise Linux 6.4 Advanced Update SupportRedHatbind-32:9.8.2-0.17.rc1.el6_4.7*
Red Hat Enterprise Linux 6.5 Advanced Update SupportRedHatbind-32:9.8.2-0.23.rc1.el6_5.2*
Red Hat Enterprise Linux 7RedHatbind-32:9.9.4-14.el7_0.1*
Bind9Ubuntudevel*
Bind9Ubuntuesm-infra-legacy/trusty*
Bind9Ubuntulucid*
Bind9Ubuntuprecise*
Bind9Ubuntutrusty*
Bind9Ubuntutrusty/esm*
Bind9Ubuntuutopic*

References