FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-0591

This CVE name corresponds to:

Entered Topic
2014-01-13 bind -- denial of service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-0591
Phase Assigned(20131227)

Description

The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

References

Source Reference
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=1051717
CONFIRM https://kb.isc.org/article/AA-01078
CONFIRM https://kb.isc.org/article/AA-01085
CONFIRM https://support.apple.com/kb/HT6536
APPLE APPLE-SA-2014-10-16-3
DEBIAN DSA-3023
FEDORA FEDORA-2014-0811
FEDORA FEDORA-2014-0858
FREEBSD FreeBSD-SA-14:04
HP HPSBUX02961
HP SSRT101420
MANDRIVA MDVSA-2014:002
REDHAT RHSA-2014:0043
SLACKWARE SSA:2014-028-01
SLACKWARE SSA:2014-175-01
SUSE openSUSE-SU-2014:0199
SUSE openSUSE-SU-2014:0202
SUSE SUSE-SU-2015:0480
UBUNTU USN-2081-1
BID 64801
OSVDB 101973
SECTRACK 1029589
SECUNIA 56425
SECUNIA 56427
SECUNIA 56442
SECUNIA 56493
SECUNIA 56522
SECUNIA 56574