PT-2014-8680 · Isc+1 · Bind+1
Publicado
2014-12-11
·
Atualizado
2024-06-15
·
CVE-2014-8680
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ISC BIND versions 9.10.0 through 9.10.1
Description
The issue is related to the GeoIP functionality, which allows remote attackers to cause a denial of service. This can happen in two scenarios: (1) when there are no GeoIP databases available for both IPv4 and IPv6, or (2) when IPv6 support is enabled with certain options, leading to an assertion failure and the named service exiting.
Recommendations
For ISC BIND versions 9.10.0 through 9.10.1, consider disabling the GeoIP functionality as a temporary workaround until a patch is available. Restrict access to the affected service to minimize the risk of exploitation.
Correção
DoS
RCE
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bind
Bind Server