QID 15150
Date Published: 2023-07-26
QID 15150: ISC BIND Crafted Query Vulnerability (CVE-2014-0591)
ISC BIND (Berkley Internet Domain Name) is an implementation of DNS protocols.
A very uncommon combination of zone data has been found that triggers a bug in BIND, with the result that named will exit with a "REQUIRE" failure in name.c when validating the data returned in answer to a recursive query.
9.6.0.x -> 9.6-ESV-R10-P1, 9.7 (all versions), 9.8.0 -> 9.8.6-P1, 9.9.0 -> 9.9.4-P1. Development releases 9.6-ESV-R11b1, 9.8.7b1, and 9.9.5b1 are also affected.
BIND Affected versions:
BIND 9.6.0.x -> 9.6-ESV-R10-P1
BIND 9.7 (all versions)
BIND 9.8.0 -> 9.8.6-P1
BIND 9.9.0 -> 9.9.4-P1
BIND 9.6-ESV-R11b1
BIND 9.9.5b1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
An unintentional defect in the handling of NSEC3-signed zones can cause BIND to be crashed by a specific set of queries.
- CVE-2014-0591 -
kb.isc.org/docs/aa-01078
CVEs related to QID 15150
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2014-0591 |
|