bind: delegation handling denial of service
Published Dec 11, 2014
7.8
HIGHCVSS 2.0
EPSS 57.79%
Description
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
Affected products
No data.
- 9.0
- 9.0.1
- 9.1
- 9.1.1
- 9.1.2
- 9.1.3
- 9.2
- 9.2.0
- 9.2.1
- 9.2.2
- 9.2.3
- 9.2.4
- 9.2.5
- 9.2.6
- 9.2.7
- 9.2.8
- 9.2.9
- 9.3
- 9.3.0
- 9.3.1
- 9.3.2
- 9.3.3
- 9.3.4
- 9.3.5
- 9.3.6
- 9.4
- 9.4.0
- 9.4.1
- 9.4.2
- 9.4.3
- 9.5
- 9.5.0
- 9.5.1
- 9.5.2
- 9.5.3
- 9.6.0
- 9.6.1
- 9.6.2
- 9.6.3
- 9.7.0
- 9.7.1
- 9.7.2
- 9.7.3
- 9.7.4
- 9.7.5
- 9.7.6
- 9.7.7
- 9.8.0
- 9.8.1
- 9.8.2
- 9.8.3
- 9.8.4
- 9.8.5
- 9.8.6
- 9.9.0
- 9.9.1
- 9.9.2
- 9.9.3
- 9.9.4
- 9.9.5
- 9.9.6
- 9.10.0
- 9.10.1
No data.
Red Hat Enterprise Linux 5
bind-30:9.3.6-25.P1.el5_11.2
Fixed · RHSA-2014:1984
Red Hat Enterprise Linux 5
bind97-32:9.7.0-21.P2.el5_11.1
Fixed · RHSA-2014:1985
Red Hat Enterprise Linux 6
bind-32:9.8.2-0.30.rc1.el6_6.1
Fixed · RHSA-2014:1984
Red Hat Enterprise Linux 6.4 Advanced Update Support
bind-32:9.8.2-0.17.rc1.el6_4.7
Fixed · RHSA-2016:0078
Red Hat Enterprise Linux 6.5 Advanced Update Support
bind-32:9.8.2-0.23.rc1.el6_5.2
Fixed · RHSA-2016:0078
Red Hat Enterprise Linux 7
bind-32:9.9.4-14.el7_0.1
Fixed · RHSA-2014:1984
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind-30:9.3.6-25.P1.el5_11.2 | Fixed | RHSA-2014:1984 |
| Red Hat Enterprise Linux 5 | bind97-32:9.7.0-21.P2.el5_11.1 | Fixed | RHSA-2014:1985 |
| Red Hat Enterprise Linux 6 | bind-32:9.8.2-0.30.rc1.el6_6.1 | Fixed | RHSA-2014:1984 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | bind-32:9.8.2-0.17.rc1.el6_4.7 | Fixed | RHSA-2016:0078 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | bind-32:9.8.2-0.23.rc1.el6_5.2 | Fixed | RHSA-2016:0078 |
| Red Hat Enterprise Linux 7 | bind-32:9.9.4-14.el7_0.1 | Fixed | RHSA-2014:1984 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 57.79% (0.57794) | 99.06th | v5 (v2026.06.15) |
| Jul 23, 2026 | 57.52% (0.57522) | 98.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 65.68% (0.65683) | 99.17th | v5 (v2026.06.15) |
| Mar 9, 2026 | 48.22% (0.48217) | 97.67th | v4 (v2025.03.14) |
| Mar 3, 2026 | 51.59% (0.51594) | 97.85th | v4 (v2025.03.14) |
| Nov 30, 2025 | 58.42% (0.58417) | 98.09th | v4 (v2025.03.14) |
| Oct 11, 2025 | 63.48% (0.63475) | 98.30th | v4 (v2025.03.14) |
| May 17, 2025 | 43.82% (0.43824) | 97.35th | v4 (v2025.03.14) |
| May 4, 2025 | 56.33% (0.56334) | 97.94th | v4 (v2025.03.14) |
| Mar 30, 2025 | 50.18% (0.50179) | 97.60th | v4 (v2025.03.14) |
| Mar 29, 2025 | 63.87% (0.63865) | 97.78th | v4 (v2025.03.14) |
| Mar 19, 2025 | 50.18% (0.50179) | 97.51th | v4 (v2025.03.14) |
| Mar 17, 2025 | 70.71% (0.70711) | 98.60th | v4 (v2025.03.14) |
| Dec 17, 2024 | 71.96% (0.71956) | 98.25th | v3 (v2023.03.01) |
| Dec 9, 2024 | 80.84% (0.80836) | 98.45th | v3 (v2023.03.01) |
| Jul 23, 2024 | 83.49% (0.83488) | 98.49th | v3 (v2023.03.01) |
| Jun 6, 2024 | 87.69% (0.87685) | 98.66th | v3 (v2023.03.01) |
| Feb 25, 2024 | 89.80% (0.89802) | 98.68th | v3 (v2023.03.01) |
| Apr 15, 2023 | 91.46% (0.91457) | 98.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 91.52% (0.91524) | 98.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 26.38% (0.26383) | 97.10th | v2 (v2022.01.01) |
| Feb 4, 2022 | 26.38% (0.26383) | 95.72th | v2 (v2022.01.01) |
References (32)
- http://advisories.mageia.org/MGASA-2014-0524.html x_refsource_CONFIRM
- http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html x_refsource_MISCVendor Advisory
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.asc vendor-advisoryx_refsource_NETBSD
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2015-07/msg00038.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=142180687100892&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=144000632319155&w=2 vendor-advisoryx_refsource_HP
- http://rhn.redhat.com/errata/RHSA-2016-0078.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/62064 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62122 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201502-03.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1031311 vdb-entryx_refsource_SECTRACK
- http://ubuntu.com/usn/usn-2437-1 vendor-advisoryx_refsource_UBUNTUPatchVendor Advisory
- http://www.debian.org/security/2014/dsa-3094 vendor-advisoryx_refsource_DEBIANVendor Advisory
- http://www.kb.cert.org/vuls/id/264212 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:165 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/71590 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2014-8500 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1171912 Issue Tracking
- https://kb.isc.org/article/AA-01216/ x_refsource_CONFIRMVendor Advisory
- https://kb.isc.org/article/AA-01216/74/CVE-2014-8500%3A-A-Defect-in-Delegation-Handling-Can-Be-Exploited-to-Crash-BIND.html
- https://nvd.nist.gov/vuln/detail/CVE-2014-8500
- https://security.netapp.com/advisory/ntap-20190730-0002/ x_refsource_CONFIRM
- https://support.apple.com/HT205219 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-8500
Change history (0)
No recorded changes yet.