CVE-2007-0494
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 44.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 44.40% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- isc/bind
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
- http://docs.info.apple.com/article.html?artnum=305530
- http://fedoranews.org/cms/node/2507
- http://fedoranews.org/cms/node/2537
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495
- http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html
- http://marc.info/?l=bind-announce&m=116968519300764&w=2
- http://secunia.com/advisories/23904Patch, Vendor Advisory
- http://secunia.com/advisories/23924Vendor Advisory
- http://secunia.com/advisories/23943Vendor Advisory
- http://secunia.com/advisories/23944Vendor Advisory
- http://secunia.com/advisories/23972Vendor Advisory
- http://secunia.com/advisories/23974Vendor Advisory
- http://secunia.com/advisories/23977Vendor Advisory
- http://secunia.com/advisories/24014Vendor Advisory
- http://secunia.com/advisories/24048Vendor Advisory
- http://secunia.com/advisories/24054Vendor Advisory
- http://secunia.com/advisories/24083Vendor Advisory
- http://secunia.com/advisories/24129Vendor Advisory
- http://secunia.com/advisories/24203Vendor Advisory
- http://secunia.com/advisories/24284
- http://secunia.com/advisories/24648Vendor Advisory
- http://secunia.com/advisories/24930Vendor Advisory
- http://secunia.com/advisories/24950Vendor Advisory
- http://secunia.com/advisories/25402Vendor Advisory
- http://secunia.com/advisories/25482
- http://secunia.com/advisories/25649
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.