[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252097

 
 

909

 
 

196747

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-0494Date: (C)2007-01-25   (M)2023-12-22


ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1017573
SUNALERT-102969
2007-0005
20070201-01-P
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
BID-22231
SECUNIA-23904
SECUNIA-23924
SECUNIA-23943
SECUNIA-23944
SECUNIA-23972
SECUNIA-23974
SECUNIA-23977
SECUNIA-24014
SECUNIA-24048
SECUNIA-24054
SECUNIA-24083
SECUNIA-24129
SECUNIA-24203
SECUNIA-24284
SECUNIA-24648
SECUNIA-24930
SECUNIA-24950
SECUNIA-25402
SECUNIA-25482
SECUNIA-25649
SECUNIA-25715
SECUNIA-26909
SECUNIA-27706
ADV-2007-1401
ADV-2007-1939
ADV-2007-2002
ADV-2007-2163
ADV-2007-2245
ADV-2007-2315
ADV-2007-3229
APPLE-SA-2007-05-24
DSA-1254
FEDORA-2007-147
FEDORA-2007-164
FreeBSD-SA-07:02
GLSA-200702-06
IY95618
IY95619
IY96144
IY96324
MDKSA-2007:030
NetBSD-SA2007-003
OpenPKG-SA-2007.007
RHSA-2007:0044
RHSA-2007:0057
SSA:2007-026-01
SSRT061273
SSRT071304
SUSE-SA:2007:014
USN-418-1
http://marc.info/?l=bind-announce&m=116968519300764&w=2
bind-rrsets-dos(31838)
http://docs.info.apple.com/article.html?artnum=305530
http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm
http://www.isc.org/index.pl?/sw/bind/bind-security.php
http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8
http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488
https://issues.rpath.com/browse/RPL-989
oval:org.mitre.oval:def:11523

CPE    92
cpe:/a:isc:bind:9.2.4:rc2
cpe:/a:isc:bind:9.0.0:rc3
cpe:/a:isc:bind:9.2.4:rc3
cpe:/a:isc:bind:9.3.1:rc1
...
CWE    1
CWE-19

© SecPod Technologies