Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-4854

35
FAUCET Score

CVE-2013-4854 describes a denial-of-service vulnerability in the RFC 5011 implementation of ISC BIND versions 9.7.x, 9.8.x, and 9.9.x, as well as DNSco BIND. A remote attacker can exploit this flaw by sending a query with a malformed RDATA section, causing the named daemon to crash. This vulnerability carries a high CVSS score of 7.8, indicating a critical impact of complete denial of service with low attack complexity and no authentication required. While it was exploited in the wild in July 2013, there is no public exploit code available, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
9.7.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.0:*:*:*:*:*:*:*
9.7.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.0:b1:*:*:*:*:*:*
9.7.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.0:p1:*:*:*:*:*:*
9.7.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.0:p2:*:*:*:*:*:*
9.7.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.7.0:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.8HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
34.15%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.3415 is in the 97th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: bind97-32:9.7.0-17.P2.el5_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: bind-32:9.8.2-0.17.rc1.el6_4.5
View patch
fedoravendor investigatingvia nvd_reference
View patch
susevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2013-4854Important

bind: named crash with an assertion failure on parsing malformed rdata

Jul 26, 2013

References

archives.neohapsis.com / archives/bugtraq/2013-08/0030.html
archives.neohapsis.com / archives/bugtraq/2014-10/0103.html
linux.oracle.com / errata/ELSA-2014-1244
lists.fedoraproject.org / pipermail/package-announce/2013-August/113108.html
Vendor Advisory
lists.fedoraproject.org / pipermail/package-announce/2013-August/113251.html
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2013-08/msg00004.html
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2013-08/msg00018.html
Vendor Advisory
rhn.redhat.com / errata/RHSA-2013-1114.html
Vendor Advisory
rhn.redhat.com / errata/RHSA-2013-1115.html
Vendor Advisory
secunia.com / advisories/54134
Vendor Advisory
secunia.com / advisories/54185
Vendor Advisory
secunia.com / advisories/54207
Vendor Advisory
secunia.com / advisories/54211
Vendor Advisory
secunia.com / advisories/54323
Vendor Advisory
secunia.com / advisories/54432
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/86004
h20564.www2.hp.com / portal/site/hpsc/public/kb/docDisplay
Vendor Advisory
kb.isc.org / article/AA-01015
Vendor Advisory
kb.isc.org / article/AA-01016
Vendor Advisory
kc.mcafee.com / corporate/index
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19561
support.apple.com / kb/HT6536
debian.org / security/2013/dsa-2728
freebsd.org / security/advisories/FreeBSD-SA-13:07.bind.asc
Vendor Advisory
mandriva.com / security/advisories
Vendor Advisory
securityfocus.com / bid/61479
securitytracker.com / id/1028838
ubuntu.com / usn/USN-1910-1
zerodayinitiative.com / advisories/ZDI-13-210