suse · CVE-2013-4854

Quick triage

Priority: medium Published: 2021-05-30 13:14:53 UTC Updated: 2026-04-18 18:51:46 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2013-4854 severity moderate: SUSE including 155 source package names (bind-9.10.3P4-21.1, bind-9.11.2-1.24, …), 242 product×package rows across 38 product lines (SUSE Linux Enterprise Desktop 11 SP2, SUSE Linux Enterprise Desktop 11 SP3, … (38 product lines)): Fixed 242.

Description:

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

cvelogic Threat Intelligence