CVE-2014-8500 describes a denial-of-service vulnerability in ISC BIND versions 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1. This flaw allows remote attackers to crash the 'named' service and consume excessive memory by exploiting unlimited delegation chaining through a large or infinite number of referrals. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.0:*:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.0.1:*:*:*:*:*:*:* | ||
9.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.1:*:*:*:*:*:*:* | ||
9.1.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.1.1:*:*:*:*:*:*:* | ||
9.1.2CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.