CVE-2013-2266: Buffer Overflow
libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2266?
CVE-2013-2266 has been classified as a medium severity vulnerability due to its potential for causing denial of service through memory exhaustion.
How do I fix CVE-2013-2266?
To mitigate CVE-2013-2266, upgrade to ISC BIND versions 9.8.4-P2, 9.8.5b2, 9.9.2-P2, or 9.9.3b2 or later.
Which BIND versions are affected by CVE-2013-2266?
CVE-2013-2266 affects ISC BIND versions 9.7.x, 9.8.x prior to 9.8.4-P2, and multiple versions of 9.9.x prior to 9.9.3b2.
What type of attack can exploit CVE-2013-2266?
CVE-2013-2266 can be exploited via crafted regular expressions, leading to a denial of service via memory consumption.
Is CVE-2013-2266 a remote vulnerability?
Yes, CVE-2013-2266 allows remote attackers to exploit the vulnerability, making it a remote denial of service risk.