Unrated severityNVD Advisory· Published Dec 11, 2014· Updated May 6, 2026
CVE-2014-8602
CVE-2014-8602
Description
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
Affected products
4cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- unbound.net/downloads/patch_cve_2014_8602.diffnvdPatch
- unbound.net/downloads/CVE-2014-8602.txtnvdPatchVendor Advisory
- cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.htmlnvdThird Party Advisory
- www.debian.org/security/2014/dsa-3097nvdThird Party Advisory
- www.kb.cert.org/vuls/id/264212nvdThird Party AdvisoryUS Government Resource
- www.ubuntu.com/usn/USN-2484-1nvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlnvd
- www.securityfocus.com/bid/71589nvd
News mentions
0No linked articles in our index yet.