ISC BIND 9 DNS RDATA Handling CVE-2013-4854 Remote Denial of Service Vulnerability
BID:61479
Info
ISC BIND 9 DNS RDATA Handling CVE-2013-4854 Remote Denial of Service Vulnerability
| Bugtraq ID: | 61479 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-4854 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2013 12:00AM |
| Updated: | Apr 13 2015 10:22PM |
| Credit: | Maxim Shudrak |
| Vulnerable: |
SuSE SUSE Linux Enterprise Software Development Kit 11 SP3 SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 SuSE SUSE Linux Enterprise Server 11 SP2 for VMware SuSE SUSE Linux Enterprise Server 11 SP2 SuSE Suse Linux Enterprise Desktop 11 SP3 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Linux Enterprise Software Development Kit 11 SP2 Slackware Linux x86_64 -current Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux -current S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 McAfee Web Gateway 7.3.2 McAfee FireWall Enterprise 8.3.1 McAfee FireWall Enterprise 8.2.1 McAfee Email Gateway 7.5 McAfee Email Gateway 7.0 McAfee Email and Web Security Appliance 5.6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 ISC Bind 9.8.4 ISC Bind 9.8 ISC Bind 9.9.3-P1 ISC Bind 9.9.3-b1 ISC Bind 9.9.3 ISC Bind 9.9.2-P2 ISC Bind 9.9.2-P1 ISC Bind 9.9.2 ISC Bind 9.9.1-P4 ISC Bind 9.9.1-P3 ISC Bind 9.9.1-P2 ISC Bind 9.9.1-P1 ISC Bind 9.9.1 ISC Bind 9.9.0 ISC Bind 9.8.5-P1 ISC Bind 9.8.5-b1 ISC Bind 9.8.5 ISC Bind 9.8.4-P2 ISC Bind 9.8.4-P1 ISC Bind 9.8.3-P4 ISC Bind 9.8.3-P3 ISC Bind 9.8.3-P2 ISC Bind 9.8.3-P1 ISC Bind 9.8.3 ISC Bind 9.8.1b1 ISC Bind 9.8.1-P1 ISC Bind 9.8.0-P4 ISC Bind 9.8.0-P3 ISC Bind 9.8.0-P2 ISC Bind 9.8.0-P1 ISC Bind 9.8.0 P4 ISC Bind 9.7.3 Infoblox NIOS 6.6 Infoblox NIOS 6.5 Infoblox NIOS 6.4 Infoblox NIOS 5.1r5-0 HP HP-UX B.11.31 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 CentOS CentOS 5 Avaya Aura Session Manager 6.3.1 Avaya Aura Session Manager 6.3 Apple Mac OS X Server 3.0 Apple Mac OS X Server 2.0 |
| Not Vulnerable: |
McAfee Web Gateway 7.3.2.2 McAfee FireWall Enterprise 8.3.1P02 ISC Bind 9.9.3-S1-P1 ISC Bind 9.9.3-P2 ISC Bind 9.8.5-P2 Infoblox NIOS 6.8.1 Infoblox NIOS 6.7.3 Infoblox NIOS 6.6.10 Infoblox NIOS 6.5.10 Infoblox NIOS 5.1r6-12 Apple Mac OS X Server 4.0 |
Exploit / POC
ISC BIND 9 DNS RDATA Handling CVE-2013-4854 Remote Denial of Service Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
References
ISC BIND 9 DNS RDATA Handling CVE-2013-4854 Remote Denial of Service Vulnerability
References:
References:
- About the security content of OS X Server v4.0 (Apple)
- bind security update (RHSA-2013-1114) (Avaya)
- CVE-2013-4854: A specially crafted query can cause BIND to terminate abnormally (ISC)
- CVE-2013-4854: FAQ and Supplemental Information (ISC)
- ISC BIND Homepage (ISC)
- McAfee Security Bulletin �?? Updates for multiple McAfee Network products resolve (McAfee)
- CVE-2013-4854: A specially crafted query sent to a BIND name server can cause it (infoblox)
- Firewall Enterprise 8.3.1P02 Release Bulletin (McAfee)
- HPSBUX02926 SSRT101281 rev.2 - HP-UX Running BIND, Remote Denial of Service (DoS (HP)
- ISC BIND rdata Denial Of Service Vulnerability (Zero Day Initiative)