First published: Thu Dec 11 2014(Updated: )
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BIND 9 | =9.10.0 | |
BIND 9 | =9.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8680 has a critical severity level as it allows remote attackers to cause denial of service.
To fix CVE-2014-8680, upgrade ISC BIND to version 9.10.2 or later where the GeoIP functionality has been patched.
CVE-2014-8680 affects ISC BIND versions 9.10.0 and 9.10.1.
CVE-2014-8680 enables remote denial of service attacks through assertion failures in the GeoIP functionality.
CVE-2014-8680 is related to both IPv4 and IPv6, specifically the lack of GeoIP databases and certain IPv6 options.