CVE-2011-4313
medium · 5query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
5
CVSS
16.2%
EPSS (exploit prob.)
97th
EPSS percentile
2011-11-29
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| isc | bind | 9.0 |
| isc | bind | 9.0.0 |
| isc | bind | 9.0.0 |
| isc | bind | 9.0.0 |
| isc | bind | 9.0.0 |
| isc | bind | 9.0.0 |
| isc | bind | 9.0.0 |
| isc | bind | 9.0.1 |
| isc | bind | 9.0.1 |
| isc | bind | 9.0.1 |
| isc | bind | 9.1 |
| isc | bind | 9.1.0 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.1 |
| isc | bind | 9.1.2 |
| isc | bind | 9.1.2 |
| isc | bind | 9.1.3 |
| isc | bind | 9.1.3 |
| isc | bind | 9.1.3 |
| isc | bind | 9.1.3 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
| isc | bind | 9.2.0 |
Check a specific version with /api/v1/cve/match.
References
- http://blogs.oracle.com/sunsecurity/entry/cve_2011_4313_denial_of
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069463.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069970.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069975.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00029.html
- http://marc.info/?l=bugtraq&m=132310123002302&w=2
- http://marc.info/?l=bugtraq&m=133978480208466&w=2
- http://marc.info/?l=bugtraq&m=141879471518471&w=2
- http://osvdb.org/77159
- http://secunia.com/advisories/46536
- http://secunia.com/advisories/46829
- http://secunia.com/advisories/46887
- http://secunia.com/advisories/46890
- http://secunia.com/advisories/46905
- http://secunia.com/advisories/46906
- http://secunia.com/advisories/46943
- http://secunia.com/advisories/46984
- http://secunia.com/advisories/47043
- http://secunia.com/advisories/47075
- http://secunia.com/advisories/48308
- http://security.freebsd.org/advisories/FreeBSD-SA-11:06.bind.asc
- http://support.apple.com/kb/HT5501
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-4313