---
cve: "CVE-2014-8500"
severity: "LOW"
cvss: 3.1
epss: "57.8%"
vendor: "n/a"
kev: false
exploited: false
published: "2014-12-11 02:00:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T09:26:49+02:00"
---

# CVE-2014-8500

> 3.1 LOW

## Beschreibung

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

## Referenzen

- <http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html>
- <http://marc.info/?l=bugtraq&m=142180687100892&w=2>
- <http://security.gentoo.org/glsa/glsa-201502-03.xml>
- <http://secunia.com/advisories/62122>
- <http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.asc>
- <https://kb.isc.org/article/AA-01216/>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2015:165>
- <http://lists.opensuse.org/opensuse-updates/2015-07/msg00038.html>
- <http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html>
- <http://secunia.com/advisories/62064>
- <http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html>
- <http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676>
- <http://www.debian.org/security/2014/dsa-3094>
- <http://securitytracker.com/id?1031311>
- <http://advisories.mageia.org/MGASA-2014-0524.html>
- <http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.html>
- <http://www.kb.cert.org/vuls/id/264212>
- <http://www.securityfocus.com/bid/71590>
- <http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html>
- <http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.html>
- <http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.html>
- <http://ubuntu.com/usn/usn-2437-1>
- <http://marc.info/?l=bugtraq&m=144000632319155&w=2>
- <http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html>
- <http://rhn.redhat.com/errata/RHSA-2016-0078.html>
- <https://support.apple.com/HT205219>
- <https://security.netapp.com/advisory/ntap-20190730-0002/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2014-8500) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
