The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Jul 29, 2013 |
| Centos_linux | — | Upgrade bind97-libsUpgrade bind-develUpgrade bind-libsUpgrade bind97-develUpgrade bind97Upgrade bind-sdbUpgrade bindUpgrade bind97-chrootUpgrade bind-chrootUpgrade bind-utilsUpgrade bind97-utils | Dec 1, 2016 | Jul 29, 2013 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jul 29, 2013 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Aug 2, 2013 | Jul 29, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 15, 2013 |
| Freebsd | — | Upgrade FreeBSDUpgrade bind98-baseUpgrade bind99-baseUpgrade bind98Upgrade bind99 | Dec 10, 2025 | Jul 26, 2013 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jul 29, 2013 |
| Hpux | — | Update NameService.BIND-AUX to the latest versionUpdate NameService.BIND-RUN to the latest version | Aug 11, 2017 | Jul 29, 2013 |
| Oracle_linux | — | Upgrade bind97-utilsUpgrade bind97-develUpgrade bind97-libsUpgrade bindUpgrade bind-sdbUpgrade bind-develUpgrade bind-chrootUpgrade bind-libsUpgrade bind97Upgrade bind-utilsUpgrade bind97-chroot | Oct 16, 2024 | Jul 26, 2013 |
| Suse | — | Upgrade bind-libs-x86Upgrade bind-libs-32bitUpgrade bind-develUpgrade bind-chrootenvUpgrade bind-docUpgrade bind-lwresdUpgrade bindUpgrade sle-sdk-releaseUpgrade bind-utilsUpgrade bind-libsUpgrade bind-devel-32bit | Feb 17, 2015 | Jul 29, 2013 |
| Ubuntu | — | Upgrade libdns95Upgrade bind9Upgrade libdns81Upgrade libdns64 | Nov 8, 2024 | Jul 29, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub