HIGH · 7.8

CVE-2013-4854

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remot...

Vulnerability Description

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
IscBind9.7.0
SuseSuse Linux Enterprise Software Development Kit11.0
NovellSuse Linux11
IscDnsco Bind9.9.3
OpensuseOpensuse11.4
FreebsdFreebsd8.0
MandrivaBusiness Server1.0
MandrivaEnterprise Server5.0
RedhatEnterprise Linux5
FedoraprojectFedora18
HpHp-Uxb.11.31
SlackwareSlackware Linux12.1

References

FAQ

What is CVE-2013-4854?

CVE-2013-4854 is a vulnerability with a CVSS score of 7.8 (HIGH). The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remot...

How severe is CVE-2013-4854?

CVE-2013-4854 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4854?

Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind, Suse Suse Linux Enterprise Software Development Kit, Novell Suse Linux, Isc Dnsco Bind, Opensuse Opensuse.