Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-4313

26
FAUCET Score

CVE-2011-4313 describes a denial-of-service vulnerability affecting multiple versions of ISC BIND, specifically versions 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1. This flaw allows remote attackers to trigger an assertion failure and cause the 'named' process to exit, leading to a denial of service. The vulnerability is related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it indicates a low-complexity attack that can be executed remotely without authentication, resulting in partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
9.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.0:*:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.0.0:rc1:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.0.0:rc2:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.0.0:rc3:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.0.0:rc4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
16.17%
Probability of exploitation in next 30 days
EPSS Percentile
96.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1617 is in the 96th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: bind-20:9.2.4-38.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: bind-30:9.3.6-16.P1.el5_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: bind97-32:9.7.0-6.P2.el5_7.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: bind-32:9.7.3-2.el6_1.P3.3
View patch

Vendor Advisories (1)

redhatCVE-2011-4313Important

bind: Remote denial of service against recursive servers via logging negative cache entry

Nov 16, 2011

References

blogs.oracle.com / sunsecurity/entry/cve_2011_4313_denial_of
lists.apple.com / archives/security-announce/2012/Sep/msg00004.html
lists.fedoraproject.org / pipermail/package-announce/2011-November/069463.html
lists.fedoraproject.org / pipermail/package-announce/2011-November/069970.html
lists.fedoraproject.org / pipermail/package-announce/2011-November/069975.html
lists.opensuse.org / opensuse-security-announce/2011-11/msg00027.html
lists.opensuse.org / opensuse-security-announce/2011-11/msg00028.html
lists.opensuse.org / opensuse-security-announce/2011-11/msg00029.html
marc.info
marc.info
marc.info
osvdb.org / 77159
secunia.com / advisories/46536
Vendor Advisory
secunia.com / advisories/46829
Vendor Advisory
secunia.com / advisories/46887
Vendor Advisory
secunia.com / advisories/46890
Vendor Advisory
secunia.com / advisories/46905
Vendor Advisory
secunia.com / advisories/46906
Vendor Advisory
secunia.com / advisories/46943
Vendor Advisory
secunia.com / advisories/46984
Vendor Advisory
secunia.com / advisories/47043
Vendor Advisory
secunia.com / advisories/47075
secunia.com / advisories/48308
security.freebsd.org / advisories/FreeBSD-SA-11:06.bind.asc
exchange.xforce.ibmcloud.com / vulnerabilities/71332
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14343
support.apple.com / kb/HT5501
www-01.ibm.com / support/docview.wss
debian.org / security/2011/dsa-2347
ibm.com / support/docview.wss
isc.org / software/bind/advisories/cve-2011-4313
PatchVendor Advisory
kb.cert.org / vuls/id/606539
US Government Resource
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2011-1458.html
redhat.com / support/errata/RHSA-2011-1459.html
redhat.com / support/errata/RHSA-2011-1496.html
securityfocus.com / bid/50690
securitytracker.com / id
ubuntu.com / usn/USN-1264-1