Vulnerability Description
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Isc | Bind | 9.0 |
Related Weaknesses (CWE)
References
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
- http://docs.info.apple.com/article.html?artnum=305530
- http://fedoranews.org/cms/node/2507
- http://fedoranews.org/cms/node/2537
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&obje
- http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html
- http://marc.info/?l=bind-announce&m=116968519300764&w=2
- http://secunia.com/advisories/23904PatchVendor Advisory
- http://secunia.com/advisories/23924Vendor Advisory
- http://secunia.com/advisories/23943Vendor Advisory
- http://secunia.com/advisories/23944Vendor Advisory
- http://secunia.com/advisories/23972Vendor Advisory
FAQ
What is CVE-2007-0494?
CVE-2007-0494 is a vulnerability with a CVSS score of 4.3 (MEDIUM). ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service ...
How severe is CVE-2007-0494?
CVE-2007-0494 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0494?
Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind.