CVE-2013-3919: High severity isc bind 9 vulnerability
resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a record in a malformed zone.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3919?
CVE-2013-3919 is rated as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2013-3919?
To mitigate CVE-2013-3919, upgrade ISC BIND to the latest version that addresses this vulnerability.
What impact does CVE-2013-3919 have on BIND servers?
CVE-2013-3919 can lead to assertion failures and crashes of the named daemon on affected BIND servers.
Which versions of ISC BIND are affected by CVE-2013-3919?
ISC BIND versions 9.6, 9.8.5, and 9.9.3 prior to their respective patch versions are affected by CVE-2013-3919.
Can CVE-2013-3919 be exploited remotely?
Yes, CVE-2013-3919 can be exploited remotely through malformed DNS queries.