CVE-2011-4313
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 16.17% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- isc/bind
- Source
- secalert@redhat.com
References
- http://blogs.oracle.com/sunsecurity/entry/cve_2011_4313_denial_of
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069463.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069970.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069975.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00029.html
- http://marc.info/?l=bugtraq&m=132310123002302&w=2
- http://marc.info/?l=bugtraq&m=133978480208466&w=2
- http://marc.info/?l=bugtraq&m=141879471518471&w=2
- http://osvdb.org/77159
- http://secunia.com/advisories/46536Vendor Advisory
- http://secunia.com/advisories/46829Vendor Advisory
- http://secunia.com/advisories/46887Vendor Advisory
- http://secunia.com/advisories/46890Vendor Advisory
- http://secunia.com/advisories/46905Vendor Advisory
- http://secunia.com/advisories/46906Vendor Advisory
- http://secunia.com/advisories/46943Vendor Advisory
- http://secunia.com/advisories/46984Vendor Advisory
- http://secunia.com/advisories/47043Vendor Advisory
- http://secunia.com/advisories/47075
- http://secunia.com/advisories/48308
- http://security.freebsd.org/advisories/FreeBSD-SA-11:06.bind.asc
- http://support.apple.com/kb/HT5501
- http://www-01.ibm.com/support/docview.wss?uid=isg1IV11106
- http://www.debian.org/security/2011/dsa-2347
- http://www.ibm.com/support/docview.wss?uid=isg1IV11248
- http://www.isc.org/software/bind/advisories/cve-2011-4313Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/606539US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.