Denial of Service (DoS) The advisory has been revoked - it doesn't affect any version of package bind  (opens in a new tab)


Threat Intelligence

EPSS
5.11% (92nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-BIND-2382051
  • published26 Jan 2022
  • disclosed6 Jun 2013
  • creditUnknown

Introduced: 6 Jun 2013

CVE-2013-3919  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

Upgrade bind to version 9.6-ESV-R9-P1, 9.8.5-P1, 9.9.3-P1 or higher.

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Denial of Service (DoS). Resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a record in a malformed zone.

References