bind: named crash with an assertion failure on parsing malformed rdata
Published Jul 26, 2013
7.8
HIGHCVSS 2.0
EPSS 34.15%
Description
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.
Affected products
No data.
Configuration 1
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.0
- 9.7.1
- 9.7.1
- 9.7.1
- 9.7.1
- 9.7.2
- 9.7.2
- 9.7.2
- 9.7.2
- 9.7.2
- 9.7.3
- 9.7.3
- 9.7.3
- 9.7.3
- 9.7.4
- 9.7.4
- 9.7.4
- 9.7.4
- 9.7.5
- 9.7.5
- 9.7.5
- 9.7.5
- 9.7.6
- 9.7.6
- 9.7.6
- 9.7.7
Configuration 2
- 11.0
- 11.0
- 11
Running on/with
- 11
Configuration 3
- 9.9.3
- 9.9.4
Configuration 5
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.0
- 9.9.1
- 9.9.1
- 9.9.1
- 9.9.2
- 9.9.3
- 9.9.3
- 9.9.3
- 9.9.3
- 9.9.3
- 9.9.3
Configuration 6
Configuration 7
- 1.0
- 5.0
Configuration 8
- 5
- 6.0
Configuration 9
- 9.8.0
- 9.8.0
- 9.8.0
- 9.8.0
- 9.8.0
- 9.8.0
- 9.8.0
- 9.8.1
- 9.8.1
- 9.8.1
- 9.8.1
- 9.8.1
- 9.8.1
- 9.8.2
- 9.8.2
- 9.8.2
- 9.8.3
- 9.8.3
- 9.8.3
- 9.8.4
- 9.8.5
- 9.8.5
- 9.8.5
- 9.8.5
- 9.8.5
- 9.8.5
- 9.8.6
Configuration 10
- 18
- 19
Configuration 12
- 12.1
- 12.2
- 13.0
- 13.1
- 13.37
No data.
Red Hat Enterprise Linux 5
bind97-32:9.7.0-17.P2.el5_9.2
Fixed · RHSA-2013:1115
Red Hat Enterprise Linux 6
bind-32:9.8.2-0.17.rc1.el6_4.5
Fixed · RHSA-2013:1114
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind97-32:9.7.0-17.P2.el5_9.2 | Fixed | RHSA-2013:1115 |
| Red Hat Enterprise Linux 6 | bind-32:9.8.2-0.17.rc1.el6_4.5 | Fixed | RHSA-2013:1114 |
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 5. It does affect the versions of bind97 as shipped with Red Hat Enterprise Linux 5 and the versions of bind as shipped with Red Hat Enterprise Linux 6.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (46 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 34.15% (0.34150) | 98.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 34.15% (0.34150) | 98.19th | v5 (v2026.06.15) |
| Apr 18, 2026 | 51.15% (0.51147) | 97.89th | v4 (v2025.03.14) |
| Mar 4, 2026 | 53.70% (0.53697) | 97.94th | v4 (v2025.03.14) |
| Mar 1, 2026 | 40.11% (0.40108) | 97.28th | v4 (v2025.03.14) |
| Feb 4, 2026 | 53.70% (0.53697) | 97.92th | v4 (v2025.03.14) |
| Feb 1, 2026 | 40.11% (0.40108) | 97.25th | v4 (v2025.03.14) |
| Jan 4, 2026 | 53.70% (0.53697) | 97.89th | v4 (v2025.03.14) |
| Jan 1, 2026 | 40.11% (0.40108) | 97.22th | v4 (v2025.03.14) |
| Dec 28, 2025 | 53.70% (0.53697) | 97.88th | v4 (v2025.03.14) |
| Dec 27, 2025 | 59.83% (0.59827) | 98.19th | v4 (v2025.03.14) |
| Dec 4, 2025 | 53.70% (0.53697) | 97.86th | v4 (v2025.03.14) |
| Dec 1, 2025 | 40.11% (0.40108) | 97.18th | v4 (v2025.03.14) |
| Nov 4, 2025 | 53.70% (0.53697) | 97.86th | v4 (v2025.03.14) |
| Nov 3, 2025 | 40.11% (0.40108) | 97.17th | v4 (v2025.03.14) |
| Nov 1, 2025 | 46.66% (0.46664) | 97.55th | v4 (v2025.03.14) |
| Oct 29, 2025 | 53.70% (0.53697) | 97.85th | v4 (v2025.03.14) |
| Oct 27, 2025 | 59.83% (0.59827) | 98.16th | v4 (v2025.03.14) |
| Oct 25, 2025 | 53.70% (0.53697) | 97.85th | v4 (v2025.03.14) |
| Oct 24, 2025 | 59.83% (0.59827) | 98.15th | v4 (v2025.03.14) |
| Oct 20, 2025 | 53.70% (0.53697) | 97.84th | v4 (v2025.03.14) |
| Oct 19, 2025 | 70.18% (0.70184) | 98.61th | v4 (v2025.03.14) |
| Oct 4, 2025 | 65.17% (0.65170) | 98.41th | v4 (v2025.03.14) |
| Oct 1, 2025 | 51.57% (0.51569) | 97.82th | v4 (v2025.03.14) |
| Sep 4, 2025 | 70.18% (0.70184) | 98.63th | v4 (v2025.03.14) |
| Sep 1, 2025 | 57.84% (0.57835) | 98.11th | v4 (v2025.03.14) |
| Aug 5, 2025 | 70.18% (0.70184) | 98.61th | v4 (v2025.03.14) |
| Aug 1, 2025 | 57.84% (0.57835) | 98.09th | v4 (v2025.03.14) |
| Jul 4, 2025 | 70.64% (0.70645) | 98.60th | v4 (v2025.03.14) |
| Jul 1, 2025 | 58.43% (0.58433) | 98.08th | v4 (v2025.03.14) |
| Jun 4, 2025 | 70.64% (0.70645) | 98.59th | v4 (v2025.03.14) |
| Jun 1, 2025 | 58.43% (0.58433) | 98.07th | v4 (v2025.03.14) |
| May 17, 2025 | 70.64% (0.70645) | 98.59th | v4 (v2025.03.14) |
| May 14, 2025 | 79.35% (0.79353) | 99.01th | v4 (v2025.03.14) |
| May 11, 2025 | 70.67% (0.70668) | 98.59th | v4 (v2025.03.14) |
| May 4, 2025 | 79.35% (0.79353) | 99.00th | v4 (v2025.03.14) |
| May 1, 2025 | 70.67% (0.70668) | 98.60th | v4 (v2025.03.14) |
| Mar 17, 2025 | 79.35% (0.79353) | 99.03th | v4 (v2025.03.14) |
| Feb 23, 2025 | 92.30% (0.92298) | 99.24th | v3 (v2023.03.01) |
| Dec 12, 2024 | 94.54% (0.94536) | 99.33th | v3 (v2023.03.01) |
| Jun 15, 2024 | 95.34% (0.95342) | 99.37th | v3 (v2023.03.01) |
| Apr 12, 2024 | 95.47% (0.95474) | 99.35th | v3 (v2023.03.01) |
| Mar 8, 2023 | 95.80% (0.95801) | 99.02th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.90% (0.96902) | 99.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 26.38% (0.26383) | 97.10th | v2 (v2022.01.01) |
| Feb 4, 2022 | 26.38% (0.26383) | 95.72th | v2 (v2022.01.01) |
No CWE recorded.
References (34)
- http://archives.neohapsis.com/archives/bugtraq/2013-08/0030.html mailing-listx_refsource_BUGTRAQ
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html vendor-advisoryx_refsource_APPLE
- http://linux.oracle.com/errata/ELSA-2014-1244 x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113108.html vendor-advisoryx_refsource_FEDORAVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113251.html vendor-advisoryx_refsource_FEDORAVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00004.html vendor-advisoryx_refsource_SUSEVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00018.html vendor-advisoryx_refsource_SUSEVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1114.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1115.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://secunia.com/advisories/54134 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54185 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54207 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54211 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54323 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/54432 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2013/dsa-2728 vendor-advisoryx_refsource_DEBIAN
- http://www.freebsd.org/security/advisories/FreeBSD-SA-13:07.bind.asc vendor-advisoryx_refsource_FREEBSDVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:202 vendor-advisoryx_refsource_MANDRIVAVendor Advisory
- http://www.securityfocus.com/bid/61479 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1028838 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-1910-1 vendor-advisoryx_refsource_UBUNTU
- http://www.zerodayinitiative.com/advisories/ZDI-13-210/ x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2013-4854 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=988999 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86004 vdb-entryx_refsource_XF
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03922396 vendor-advisoryx_refsource_HPVendor Advisory
- https://kb.isc.org/article/AA-01015 x_refsource_CONFIRMVendor Advisory
- https://kb.isc.org/article/AA-01015/74/CVE-2013-4854%3A-A-specially-crafted-query-can-cause-BIND-to-terminate-abnormally.html
- https://kb.isc.org/article/AA-01016 x_refsource_CONFIRMVendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10052 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2013-4854
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19561 vdb-entrysignaturex_refsource_OVAL
- https://support.apple.com/kb/HT6536 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2013-4854
Change history (0)
No recorded changes yet.