First published: Thu Dec 11 2014(Updated: )
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unbound | <=1.5.0 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Debian | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8602 is classified as a medium severity vulnerability due to its potential to cause denial of service through excessive resource consumption.
CVE-2014-8602 affects Unbound versions prior to 1.5.1.
To fix CVE-2014-8602, upgrade Unbound to version 1.5.1 or later.
Yes, CVE-2014-8602 is present in Ubuntu 14.04 if an unpatched version of Unbound is used.
Yes, CVE-2014-8602 can be exploited remotely by sending a large or infinite number of referrals.