CVE-2014-0591: Buffer Overflow
It was reported that a defect in how BIND handled queries for NSEC3-signed zones could cause a crash of the named daemon with an "INSIST" failure when processing queries that possessed certain properties.
A remote attacker could exploit this defect by constructing a carefully-crafted query against an authoritative nameserver that served NSEC3-signed zones.
Note that this flaw affects BIND versions 9.6.0 and higher (NSEC3 was introduced in BIND 9.6.0 but is not automatically enabled). Authoritative nameservers that are serving at least one NSEC3-signed zone are vulnerable. Authoritative nameservers that are NOT serving at least one NSEC3-signed zone are not vulnerable, nor are recursive-only servers. Servers running versions of BIND older than 9.6.0 are also not vulnerable.
There are no workarounds for this issue.
Other sources
The queryfindclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.6 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.8.6 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.9.4 - Upgrade
Upgrade
ISC BIND namedto a version that resolves this vulnerability.Fixed in 9.8.6-P2 - Upgrade
Upgrade
ISC BIND namedto a version that resolves this vulnerability.Fixed in 9.9.4-P2 - Upgrade
Upgrade
ISC BIND namedto a version that resolves this vulnerability.Fixed in 9.6-ESV-R10-P2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0591?
CVE-2014-0591 has been rated as a high severity vulnerability due to its potential to cause the BIND named daemon to crash.
How do I fix CVE-2014-0591?
To fix CVE-2014-0591, update BIND to a version higher than 9.6, 9.8.6, or 9.9.4, ensuring you apply the latest security patches.
What versions of BIND are affected by CVE-2014-0591?
CVE-2014-0591 affects BIND versions 9.6, 9.8.6, and 9.9.4 and earlier releases.
Can CVE-2014-0591 be exploited remotely?
Yes, CVE-2014-0591 can be exploited remotely by an attacker sending specially crafted queries to the vulnerable BIND server.
Is there a workaround for CVE-2014-0591 if I cannot update BIND?
There is no recommended workaround for CVE-2014-0591; updating to a safe version is essential to mitigate the risk.