Vulnerability Details CVE-2013-4854
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.707
EPSS Ranking 98.6%
CVSS Severity
CVSS v2 Score 7.8
Products affected by CVE-2013-4854
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:isc:dnsco_bind:9.9.3
-
cpe:2.3:a:isc:dnsco_bind:9.9.4
-
cpe:2.3:a:suse:suse_linux_enterprise_software_development_kit:11.0
-
cpe:2.3:o:fedoraproject:fedora:18
-
cpe:2.3:o:fedoraproject:fedora:19
-
cpe:2.3:o:freebsd:freebsd:8.0
-
cpe:2.3:o:freebsd:freebsd:8.1
-
cpe:2.3:o:freebsd:freebsd:8.2
-
cpe:2.3:o:freebsd:freebsd:8.3
-
cpe:2.3:o:freebsd:freebsd:8.4
-
cpe:2.3:o:freebsd:freebsd:9.0
-
cpe:2.3:o:freebsd:freebsd:9.1
-
cpe:2.3:o:freebsd:freebsd:9.2
-
cpe:2.3:o:hp:hp-ux:b.11.31
-
cpe:2.3:o:mandriva:business_server:1.0
-
cpe:2.3:o:mandriva:enterprise_server:5.0
-
cpe:2.3:o:novell:suse_linux:11
-
cpe:2.3:o:opensuse:opensuse:11.4
-
cpe:2.3:o:redhat:enterprise_linux:5
-
cpe:2.3:o:redhat:enterprise_linux:6.0
-
cpe:2.3:o:slackware:slackware_linux:12.1
-
cpe:2.3:o:slackware:slackware_linux:12.2
-
cpe:2.3:o:slackware:slackware_linux:13.0
-
cpe:2.3:o:slackware:slackware_linux:13.1
-
cpe:2.3:o:slackware:slackware_linux:13.37