CVE-2014-0591: ISC BIND
Low severity, CVSS 2.6. EPSS: 31.7% chance of exploitation in the next 30 days.
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
Affected products
- ISC BIND: version 9.6 only; version 9.6.0 only; version 9.6.1 only; version 9.6.2 only; version 9.6.3 only; version 9.7.0 only; …
Published 2014-01-14. Last modified 2026-06-17.