PT-2014-8680 · Isc+1 · Bind+1
Published
2014-12-11
·
Updated
2024-06-15
·
CVE-2014-8680
CVSS v2.0
5.4
Medium
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ISC BIND versions 9.10.0 through 9.10.1
Description
The issue is related to the GeoIP functionality, which allows remote attackers to cause a denial of service. This can happen in two scenarios: (1) when there are no GeoIP databases available for both IPv4 and IPv6, or (2) when IPv6 support is enabled with certain options, leading to an assertion failure and the named service exiting.
Recommendations
For ISC BIND versions 9.10.0 through 9.10.1, consider disabling the GeoIP functionality as a temporary workaround until a patch is available. Restrict access to the affected service to minimize the risk of exploitation.
Fix
DoS
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bind
Bind Server