CVE-2014-3859: ISC BIND

Medium severity, CVSS 5.0. EPSS: 7% chance of exploitation in the next 30 days.

libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.

Affected products

  • ISC BIND: version 9.10.0 only

Published 2014-06-13. Last modified 2026-06-17.