← Vulnerability feed

Vulnerability record · CVE-2014-0591 · published 14 January 2014

CVE-2014-0591: Isc bind memory buffer overflow vulnerability

Isc · Bind

The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

2.6 CVSS 2.0 Low EPSS 32% · top 1.8% CWE-119 · Memory buffer overflow
2.6CVSS 2.0 base score
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
64References
17 Jun 2026Last modified by NVD

Description

The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.

AV:N/AC:H/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html
http://linux.oracle.com/errata/ELSA-2014-1244
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00016.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00019.html
http://marc.info/?l=bugtraq&m=138995561732658&w=2
http://osvdb.org/101973
http://rhn.redhat.com/errata/RHSA-2014-0043.html
http://secunia.com/advisories/56425
http://secunia.com/advisories/56427
http://secunia.com/advisories/56442
http://secunia.com/advisories/56493
http://secunia.com/advisories/56522
http://secunia.com/advisories/56574
http://secunia.com/advisories/56871
http://secunia.com/advisories/61117
http://secunia.com/advisories/61199
http://secunia.com/advisories/61343
http://www.debian.org/security/2014/dsa-3023
http://www.freebsd.org/security/advisories/FreeBSD-SA-14:04.bind.asc
http://www.mandriva.com/security/advisories?name=MDVSA-2014:002
http://www.securityfocus.com/bid/64801
http://www.securitytracker.com/id/1029589
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.518391
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2014&m=slackware-security.524465
http://www.ubuntu.com/usn/USN-2081-1
https://bugzilla.redhat.com/show_bug.cgi?id=1051717
https://kb.isc.org/article/AA-01078 Vendor Advisory
https://kb.isc.org/article/AA-01085 Vendor Advisory
https://support.apple.com/kb/HT6536
http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html
http://linux.oracle.com/errata/ELSA-2014-1244
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126761.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126772.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00016.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00019.html
http://marc.info/?l=bugtraq&m=138995561732658&w=2

Track CVE-2014-0591 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-0591), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.