All errata/sisyphus/ALT-PU-2014-1137-1
ALT-PU-2014-1137-1

Package update bind in branch sisyphus

Version9.9.5-alt1
Published2014-02-03
Max severityLOW
Severity:

Closed issues (1)

CVE-2014-0591
LOW2.6

The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

Published: 2014-01-14Modified: 2026-04-29
CVSS 2.0LOW 2.6
CVSS:2.0/AV:N/AC:H/Au:N/C:N/I:N/A:P
References