CVE-2014-3214: Input Validation
Published May 9, 2014
·Updated
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
Affected Software
1 affected component
ISC BIND=9.10.0
Event History
May 9, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3214?
CVE-2014-3214 is classified as a denial of service vulnerability.
2
How do I fix CVE-2014-3214?
To resolve CVE-2014-3214, upgrade ISC BIND to version 9.10.1 or later.
3
Who is affected by CVE-2014-3214?
CVE-2014-3214 affects ISC BIND version 9.10.0 when used as a recursive nameserver.
4
What type of attack does CVE-2014-3214 facilitate?
CVE-2014-3214 allows remote attackers to cause a denial of service by sending a specific DNS query.
5
What impact does CVE-2014-3214 have on the system?
CVE-2014-3214 results in an assertion failure and causes the daemon to exit, leading to a service outage.