CVE-2013-3919: ISC BIND

High severity, CVSS 7.8. EPSS: 5.1% chance of exploitation in the next 30 days.

resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a record in a malformed zone.

Affected products

  • ISC BIND: version 9.6 only; version 9.8.5 only; version 9.9.3 only

Published 2013-06-06. Last modified 2026-06-16.