CVE-2013-6230: Medium severity ISC BIND vulnerability
The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does not properly support the SIOGETINTERFACELIST command for netmask 255.255.255.255, which allows remote attackers to bypass intended IP address restrictions by leveraging misinterpretation of this netmask as a 0.0.0.0 netmask.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ISC BIND 9.6-ESVto a version that resolves this vulnerability.Fixed in 9.6-ESV-R10-P1 - Upgrade
Upgrade
ISC BIND 9.8to a version that resolves this vulnerability.Fixed in 9.8.6-P1 - Upgrade
Upgrade
ISC BIND 9.9to a version that resolves this vulnerability.Fixed in 9.9.4-P1 - Upgrade
Upgrade
ISC BIND 9.9.3-S1to a version that resolves this vulnerability.Fixed in 9.9.3-S1 - Upgrade
Upgrade
ISC BIND 9.9.4-S1to a version that resolves this vulnerability.Fixed in 9.9.4-S1
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2013-6230?
Exploitation of CVE-2013-6230 may allow a remote attacker to cause a denial of service or execute arbitrary code.
How do I fix CVE-2013-6230?
To fix CVE-2013-6230, upgrade your ISC BIND to one of the patched versions, such as 9.6-ESV-R10-P1 or 9.9.4-P1.
Which versions of ISC BIND are affected by CVE-2013-6230?
CVE-2013-6230 affects ISC BIND versions 9.6-ESV prior to 9.6-ESV-R10-P1, and versions 9.8 and 9.9 prior to specific patch releases.
What type of vulnerability is CVE-2013-6230 classified as?
CVE-2013-6230 is classified as a remote code execution vulnerability due to improper handling of the SIO_GET_INTERFACE_LIST command.
Is there a workaround for CVE-2013-6230 if I cannot upgrade immediately?
While a definitive workaround is not available, implementing strict firewall rules and monitoring could help mitigate the risk until an upgrade is possible.