CVE-2014-0591: Buffer Overflow

Published Jan 11, 2014
·
Updated

It was reported that a defect in how BIND handled queries for NSEC3-signed zones could cause a crash of the named daemon with an "INSIST" failure when processing queries that possessed certain properties.

A remote attacker could exploit this defect by constructing a carefully-crafted query against an authoritative nameserver that served NSEC3-signed zones.

Note that this flaw affects BIND versions 9.6.0 and higher (NSEC3 was introduced in BIND 9.6.0 but is not automatically enabled). Authoritative nameservers that are serving at least one NSEC3-signed zone are vulnerable. Authoritative nameservers that are NOT serving at least one NSEC3-signed zone are not vulnerable, nor are recursive-only servers. Servers running versions of BIND older than 9.6.0 are also not vulnerable.

There are no workarounds for this issue.

Other sources

The queryfindclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

MITRE

Affected Software

91 affected componentsFixes available
redhat/bind<9.6
9.6
redhat/bind<9.8.6
9.8.6
redhat/bind<9.9.4
9.9.4
ISC BIND=9.6
ISC BIND=9.6-r5_p1
ISC BIND=9.6-r6_b1
ISC BIND=9.6-r6_rc1
ISC BIND=9.6-r6_rc2
ISC BIND=9.6-r7_p1
ISC BIND=9.6-r7_p2
ISC BIND=9.6-r9_p1
ISC BIND=9.6.0
ISC BIND=9.6.0-p1
ISC BIND=9.6.0-rc1
ISC BIND=9.6.0-rc2
ISC BIND=9.6.1
ISC BIND=9.6.1-p1
ISC BIND=9.6.1-p2
ISC BIND=9.6.1-p3
ISC BIND=9.6.1-rc1
ISC BIND=9.6.2
ISC BIND=9.6.2-rc1
ISC BIND=9.6.3
ISC BIND=9.6.3-rc1
ISC BIND=9.7.0
ISC BIND=9.7.0-b1
ISC BIND=9.7.0-p1
ISC BIND=9.7.0-p2
ISC BIND=9.7.0-rc1
ISC BIND=9.7.0-rc2
ISC BIND=9.7.1
ISC BIND=9.7.1-p1
ISC BIND=9.7.1-p2
ISC BIND=9.7.1-rc1
ISC BIND=9.7.2
ISC BIND=9.7.2-p1
ISC BIND=9.7.2-p2
ISC BIND=9.7.2-p3
ISC BIND=9.7.2-rc1
ISC BIND=9.7.3
ISC BIND=9.7.3-b1
ISC BIND=9.7.3-p1
ISC BIND=9.7.3-rc1
ISC BIND=9.7.4
ISC BIND=9.7.4-b1
ISC BIND=9.7.4-p1
ISC BIND=9.7.4-rc1
ISC BIND=9.7.5
ISC BIND=9.7.5-b1
ISC BIND=9.7.5-rc1
ISC BIND=9.7.5-rc2
ISC BIND=9.7.6
ISC BIND=9.7.6-p1
ISC BIND=9.7.6-p2
ISC BIND=9.7.7
ISC BIND=9.8.0
ISC BIND=9.8.0-a1
ISC BIND=9.8.0-b1
ISC BIND=9.8.0-p1
ISC BIND=9.8.0-p2
ISC BIND=9.8.0-p4
ISC BIND=9.8.0-rc1
ISC BIND=9.8.1
ISC BIND=9.8.1-b1
ISC BIND=9.8.1-b2
ISC BIND=9.8.1-b3
ISC BIND=9.8.1-p1
ISC BIND=9.8.1-rc1
ISC BIND=9.8.2-b1
ISC BIND=9.8.2-rc1
ISC BIND=9.8.2-rc2
ISC BIND=9.8.3
ISC BIND=9.8.3-p1
ISC BIND=9.8.3-p2
ISC BIND=9.8.4
ISC BIND=9.8.5
ISC BIND=9.8.5-b1
ISC BIND=9.8.5-b2
ISC BIND=9.8.5-p1
ISC BIND=9.8.5-p2
ISC BIND=9.8.5-rc1
ISC BIND=9.8.5-rc2
ISC BIND=9.8.6
ISC BIND=9.8.6-b1
ISC BIND=9.8.6-p1
ISC BIND=9.8.6-rc1
ISC BIND=9.8.6-rc2
ISC BIND=9.9.4
ISC BIND=9.9.4-p1
ISC BIND=9.9.4-rc1
ISC BIND=9.9.4-rc2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/bind to a version that resolves this vulnerability.

    Fixed in 9.6
  2. Upgrade

    Upgrade redhat/bind to a version that resolves this vulnerability.

    Fixed in 9.8.6
  3. Upgrade

    Upgrade redhat/bind to a version that resolves this vulnerability.

    Fixed in 9.9.4
  4. Upgrade

    Upgrade ISC BIND named to a version that resolves this vulnerability.

    Fixed in 9.8.6-P2
  5. Upgrade

    Upgrade ISC BIND named to a version that resolves this vulnerability.

    Fixed in 9.9.4-P2
  6. Upgrade

    Upgrade ISC BIND named to a version that resolves this vulnerability.

    Fixed in 9.6-ESV-R10-P2

Event History

Jan 14, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-0591?

CVE-2014-0591 has been rated as a high severity vulnerability due to its potential to cause the BIND named daemon to crash.

2

How do I fix CVE-2014-0591?

To fix CVE-2014-0591, update BIND to a version higher than 9.6, 9.8.6, or 9.9.4, ensuring you apply the latest security patches.

3

What versions of BIND are affected by CVE-2014-0591?

CVE-2014-0591 affects BIND versions 9.6, 9.8.6, and 9.9.4 and earlier releases.

4

Can CVE-2014-0591 be exploited remotely?

Yes, CVE-2014-0591 can be exploited remotely by an attacker sending specially crafted queries to the vulnerable BIND server.

5

Is there a workaround for CVE-2014-0591 if I cannot update BIND?

There is no recommended workaround for CVE-2014-0591; updating to a safe version is essential to mitigate the risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203