PT-2014-8680 · Isc+1 · Bind+1

Published

2014-12-11

·

Updated

2024-06-15

·

CVE-2014-8680

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC BIND versions 9.10.0 through 9.10.1
Description The issue is related to the GeoIP functionality, which allows remote attackers to cause a denial of service. This can happen in two scenarios: (1) when there are no GeoIP databases available for both IPv4 and IPv6, or (2) when IPv6 support is enabled with certain options, leading to an assertion failure and the named service exiting.
Recommendations For ISC BIND versions 9.10.0 through 9.10.1, consider disabling the GeoIP functionality as a temporary workaround until a patch is available. Restrict access to the affected service to minimize the risk of exploitation.

Fix

DoS

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8680
OPENSUSE-SU-2024:10467-1

Affected Products

Bind
Bind Server