LWN.net Logo

bind9: denial of service

Package(s):bind9 CVE #(s):CVE-2013-4854
Created:July 29, 2013 Updated:August 19, 2013
Description: From the CVE entry:

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

Alerts:
Debian DSA-2728-1 2013-07-27
Mageia MGASA-2013-0237 2013-07-29
Mandriva MDVSA-2013:202 2013-07-29
Ubuntu USN-1910-1 2013-07-29
Red Hat RHSA-2013:1114-01 2013-07-30
Red Hat RHSA-2013:1115-01 2013-07-30
CentOS CESA-2013:1114 2013-07-30
CentOS CESA-2013:1115 2013-07-30
Oracle ELSA-2013-1115 2013-07-30
Scientific Linux SL-bind-20130730 2013-07-30
Scientific Linux SL-bind-20130730 2013-07-30
Oracle ELSA-2013-1114 2013-07-30
Fedora FEDORA-2013-13863 2013-08-02
Fedora FEDORA-2013-13831 2013-08-04
Slackware SSA:2013-218-01 2013-08-06
SUSE SUSE-SU-2013:1310-1 2013-08-07
openSUSE openSUSE-SU-2013:1353-1 2013-08-19
openSUSE openSUSE-SU-2013:1354-1 2013-08-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds