Vulnerability Report

CVE-2014-0591

Title: Isc Bind Memory Corruption

Memory Corruption

Proof Of Concept

No public PoC currently indexed for CVE-2014-0591.

CWE Category CWE-119
Published Date Jan 14, 2014
Modified Date Jun 17, 2026
Exploit Status Not Found
Score 2.6 CVSS v2.0
Exploit Probability (EPSS)
31.67%

Vulnerability Summary

CVE-2014-0591: The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

Impacted Vendors

Reference Links

http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html http://linux.oracle.com/errata/ELSA-2014-1244 http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.html http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.html http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html http://lists.opensuse.org/opensuse-updates/2014-02/msg00016.html http://lists.opensuse.org/opensuse-updates/2014-02/msg00019.html http://marc.info/?l=bugtraq&m=138995561732658&w=2 http://osvdb.org/101973 http://rhn.redhat.com/errata/RHSA-2014-0043.html http://secunia.com/advisories/56425 http://secunia.com/advisories/56427 http://secunia.com/advisories/56442 http://secunia.com/advisories/56493 http://secunia.com/advisories/56522 http://secunia.com/advisories/56574 http://secunia.com/advisories/56871 http://secunia.com/advisories/61117 http://secunia.com/advisories/61199 http://secunia.com/advisories/61343 http://www.debian.org/security/2014/dsa-3023 http://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.asc http://www.mandriva.com/security/advisories?name=MDVSA-2014:002 http://www.securityfocus.com/bid/64801 http://www.securitytracker.com/id/1029589 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.518391 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.524465 http://www.ubuntu.com/usn/USN-2081-1 https://bugzilla.redhat.com/show_bug.cgi?id=1051717 https://kb.isc.org/article/AA-01078 https://kb.isc.org/article/AA-01085 https://support.apple.com/kb/HT6536 http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html http://linux.oracle.com/errata/ELSA-2014-1244 http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.html http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.html http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html http://lists.opensuse.org/opensuse-updates/2014-02/msg00016.html http://lists.opensuse.org/opensuse-updates/2014-02/msg00019.html http://marc.info/?l=bugtraq&m=138995561732658&w=2 http://osvdb.org/101973 http://rhn.redhat.com/errata/RHSA-2014-0043.html http://secunia.com/advisories/56425 http://secunia.com/advisories/56427 http://secunia.com/advisories/56442 http://secunia.com/advisories/56493 http://secunia.com/advisories/56522 http://secunia.com/advisories/56574 http://secunia.com/advisories/56871 http://secunia.com/advisories/61117 http://secunia.com/advisories/61199 http://secunia.com/advisories/61343 http://www.debian.org/security/2014/dsa-3023 http://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.asc http://www.mandriva.com/security/advisories?name=MDVSA-2014:002 http://www.securityfocus.com/bid/64801 http://www.securitytracker.com/id/1029589 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.518391 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.524465 http://www.ubuntu.com/usn/USN-2081-1 https://bugzilla.redhat.com/show_bug.cgi?id=1051717 https://kb.isc.org/article/AA-01078 https://kb.isc.org/article/AA-01085 https://support.apple.com/kb/HT6536
CVSS v2.0
Source Entity [email protected]
Severity LOW
2.6
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:H/Au:N/C:N/I:N/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2014-0591 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:H/Au:N/C:N/I:N/A:P

Affected Stack

No specific products linked.