← Back

CVE-2013-6230

nvd nist
Published: Nov 8, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does not properly support the SIO_GET_INTERFACE_LIST command for netmask 255.255.255.255, which allows remote attackers to bypass intended IP address restrictions by leveraging misinterpretation of this netmask as a 0.0.0.0 netmask.

Affected (58)

Products: Isc: Bind
1 product
Bind
Configuration A
58 vulnerable
Vulnerable SoftwareAffected Versions
Isc
Version 9.6
Version 9.6 r5_p1
Version 9.6 r6_b1
Version 9.6 r6_rc1
Version 9.6 r6_rc2
Version 9.6 r7_p1
Version 9.6 r7_p2
Version 9.6 r9_p1
Version 9.8.0
Version 9.8.0 a1
Version 9.8.0 b1
Version 9.8.0 p1
Version 9.8.0 p2
Version 9.8.0 p4
Version 9.8.0 rc1
Version 9.8.1
Version 9.8.1 b1
Version 9.8.1 b2
Version 9.8.1 b3
Version 9.8.1 p1
Version 9.8.1 rc1
Version 9.8.2 b1
Version 9.8.2 rc1
Version 9.8.2 rc2
Version 9.8.3
Version 9.8.3 p1
Version 9.8.3 p2
Version 9.8.4
Version 9.8.5
Version 9.8.5 b1
Version 9.8.5 b2
Version 9.8.5 p1
Version 9.8.5 p2
Version 9.8.5 rc1
Version 9.8.5 rc2
Version 9.8.6 b1
Version 9.9.0
Version 9.9.0 a1
Version 9.9.0 a2
Version 9.9.0 a3
Version 9.9.0 b1
Version 9.9.0 b2
Version 9.9.0 rc1
Version 9.9.0 rc2
Version 9.9.0 rc3
Version 9.9.0 rc4
Version 9.9.1
Version 9.9.1 p1
Version 9.9.1 p2
Version 9.9.2
Version 9.9.3
Version 9.9.3 b1
Version 9.9.3 b2
Version 9.9.3 p1
Version 9.9.3 p2
Version 9.9.3 rc1
Version 9.9.3 rc2
Version 9.9.4 b1

Related CWEs

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.