CVE-2011-4313
published 2011-11-29CVE-2011-4313: query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
16.17%
96.6th percentile
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.8.1.dfsg.P1-1 (bookworm) | bind9 1:9.8.1.dfsg.P1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-11:06.bind: Remote packet Denial of Service against named(8) servers
bsd_advisories·2011-12-23·CVSS 5.0
CVE-2011-4313 [MEDIUM] FreeBSD-SA-11:06.bind: Remote packet Denial of Service against named(8) servers
FreeBSD-SA-11:06.bind Security Advisory
The FreeBSD Project
Topic: Remote packet Denial of Service against named(8) servers
Category: contrib
Module: bind
Announced: 2011-12-23
Affects: All supported versions of FreeBSD.
Corrected: 2011-11-17 01:10:16 UTC (RELENG_7, 7.4-STABLE)
2011-12-23 15:00:37 UTC (RELENG_7_4, 7.4-RELEASE-p5)
2011-12-23 15:00:37 UTC (RELENG_7_3, 7.3-RELEASE-p9)
2011-11-17 00:36:10 UTC (RELENG_8, 8.2-STABLE)
2011-12-23 15:00:37 UTC (RELENG_8_2, 8.2-RELEASE-p5)
2011-12-23 15:00:37 UTC (RELENG_8_1, 8.1-RELEASE-p7)
2011-12-01 21:13:41 UTC (RELENG_9, 9.0-STABLE)
2011-12-01 21:17:59 UTC (RELENG_9_0, 9.0-RC3)
2011-11-16 23:41:13 UTC (ports tree)
CVE Name: CVE-2011-4313
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above
Red Hat
bind: Remote denial of service against recursive servers via logging negative cache entry
vendor_redhat·2011-11-16·CVSS 5.0
CVE-2011-4313 [MEDIUM] bind: Remote denial of service against recursive servers via logging negative cache entry
bind: Remote denial of service against recursive servers via logging negative cache entry
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
Ubuntu
Bind vulnerability
vendor_ubuntu·2011-11-16
CVE-2011-4313 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled certain specially crafted
packets. A remote attacker could use this flaw to cause Bind to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-4313: bind9 - query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV thr...
vendor_debian·2011·CVSS 5.0
CVE-2011-4313 [MEDIUM] CVE-2011-4313: bind9 - query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV thr...
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-1)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-1)
sid: resolved (fixed in 1:9.8.1.dfsg.P1-1)
trixie: resolved (fixed in 1:9.8.1.dfsg.P1-1)
GHSA
GHSA-57gh-wgq6-m27j: query
ghsa_unreviewed·2022-05-14
CVE-2011-4313 [MEDIUM] GHSA-57gh-wgq6-m27j: query
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
OSV
CVE-2011-4313: query
osv·2011-11-29·CVSS 5.0
CVE-2011-4313 [MEDIUM] CVE-2011-4313: query
query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.
No detection rules found.
No public exploits indexed.
http://blogs.oracle.com/sunsecurity/entry/cve_2011_4313_denial_ofhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069463.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069970.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069975.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00029.htmlhttp://marc.info/?l=bugtraq&m=132310123002302&w=2http://marc.info/?l=bugtraq&m=133978480208466&w=2http://marc.info/?l=bugtraq&m=141879471518471&w=2http://osvdb.org/77159http://secunia.com/advisories/46536http://secunia.com/advisories/46829http://secunia.com/advisories/46887http://secunia.com/advisories/46890http://secunia.com/advisories/46905http://secunia.com/advisories/46906http://secunia.com/advisories/46943http://secunia.com/advisories/46984http://secunia.com/advisories/47043http://secunia.com/advisories/47075http://secunia.com/advisories/48308http://security.freebsd.org/advisories/FreeBSD-SA-11:06.bind.aschttp://support.apple.com/kb/HT5501http://www-01.ibm.com/support/docview.wss?uid=isg1IV11106http://www.debian.org/security/2011/dsa-2347http://www.ibm.com/support/docview.wss?uid=isg1IV11248http://www.isc.org/software/bind/advisories/cve-2011-4313http://www.kb.cert.org/vuls/id/606539http://www.mandriva.com/security/advisories?name=MDVSA-2011:176http://www.redhat.com/support/errata/RHSA-2011-1458.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1459.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1496.htmlhttp://www.securityfocus.com/bid/50690http://www.securitytracker.com/id?1026335http://www.ubuntu.com/usn/USN-1264-1https://exchange.xforce.ibmcloud.com/vulnerabilities/71332https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14343http://blogs.oracle.com/sunsecurity/entry/cve_2011_4313_denial_ofhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069463.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069970.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/069975.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00029.htmlhttp://marc.info/?l=bugtraq&m=132310123002302&w=2http://marc.info/?l=bugtraq&m=133978480208466&w=2http://marc.info/?l=bugtraq&m=141879471518471&w=2http://osvdb.org/77159http://secunia.com/advisories/46536http://secunia.com/advisories/46829http://secunia.com/advisories/46887http://secunia.com/advisories/46890http://secunia.com/advisories/46905http://secunia.com/advisories/46906http://secunia.com/advisories/46943http://secunia.com/advisories/46984http://secunia.com/advisories/47043http://secunia.com/advisories/47075http://secunia.com/advisories/48308http://security.freebsd.org/advisories/FreeBSD-SA-11:06.bind.aschttp://support.apple.com/kb/HT5501http://www-01.ibm.com/support/docview.wss?uid=isg1IV11106http://www.debian.org/security/2011/dsa-2347http://www.ibm.com/support/docview.wss?uid=isg1IV11248http://www.isc.org/software/bind/advisories/cve-2011-4313http://www.kb.cert.org/vuls/id/606539http://www.mandriva.com/security/advisories?name=MDVSA-2011:176http://www.redhat.com/support/errata/RHSA-2011-1458.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1459.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1496.htmlhttp://www.securityfocus.com/bid/50690http://www.securitytracker.com/id?1026335http://www.ubuntu.com/usn/USN-1264-1https://exchange.xforce.ibmcloud.com/vulnerabilities/71332https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14343
2011-11-29
Published