CVE-2014-3859: Input Validation
Published Jun 13, 2014
·Updated
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.
Affected Software
1 affected component
ISC BIND=9.10.0
Event History
Jun 13, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:19 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3859?
CVE-2014-3859 has a severity rating that indicates it could lead to a denial of service vulnerability.
2
How do I fix CVE-2014-3859?
To fix CVE-2014-3859, upgrade ISC BIND to version 9.10.0-P2 or later.
3
What types of attacks can exploit CVE-2014-3859?
CVE-2014-3859 can be exploited through crafted packets that manipulate EDNS options.
4
What are the symptoms of CVE-2014-3859 being exploited?
Symptoms of CVE-2014-3859 exploitation include assertion failures and unexpected daemon exits in affected BIND instances.
5
Is CVE-2014-3859 specific to certain versions of BIND?
Yes, CVE-2014-3859 specifically affects ISC BIND version 9.10.0 prior to P2.