CVE-2007-0493
published 2007-01-25CVE-2007-0493: Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
12.08%
95.7th percentile
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.3.4-2 (bookworm) | bind9 1:9.3.4-2 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.3.4-2 | 1:9.3.4-2 |
| isc | bind9 | >= 0 < 1:9.3.4-2 | 1:9.3.4-2 |
| isc | bind9 | >= 0 < 1:9.3.4-2 | 1:9.3.4-2 |
| isc | bind9 | >= 0 < 1:9.3.4-2 | 1:9.3.4-2 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8MEDIUM
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-07:02.bind: Multiple Denial of Service vulnerabilities in named(8)
bsd_advisories·2007-02-09·CVSS 7.8
CVE-2007-0493 [HIGH] FreeBSD-SA-07:02.bind: Multiple Denial of Service vulnerabilities in named(8)
FreeBSD-SA-07:02.bind Security Advisory
The FreeBSD Project
Topic: Multiple Denial of Service vulnerabilities in named(8)
Category: contrib
Module: bind
Announced: 2007-02-09
Affects: FreeBSD 5.3 and later.
Corrected: 2007-02-07 00:42:09 UTC (RELENG_6, 6.2-STABLE)
2007-02-09 20:24:15 UTC (RELENG_6_2, 6.2-RELEASE-p1)
2007-02-09 20:23:29 UTC (RELENG_6_1, 6.1-RELEASE-p13)
2007-02-07 00:46:35 UTC (RELENG_5, 5.5-STABLE)
2007-02-09 20:22:44 UTC (RELENG_5_5, 5.5-RELEASE-p11)
CVE Name: CVE-2007-0493, CVE-2007-0494
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Int
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2007-02-06
CVE-2007-0493 Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind vulnerabilities
A flaw was discovered in Bind's DNSSEC validation code. Remote
attackers could send a specially crafted DNS query which would cause the
Bind server to crash, resulting in a denial of service. Only servers
configured to use DNSSEC extensions were vulnerable.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
bind use-after-free
vendor_redhat·2007-01-25·CVSS 7.8
CVE-2007-0493 [HIGH] CWE-416 bind use-after-free
bind use-after-free
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
Statement: Not vulnerable. This issue did not affect the versions of ISC BIND as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.
Debian
CVE-2007-0493: bind9 - Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a...
vendor_debian·2007·CVSS 7.8
CVE-2007-0493 [HIGH] CVE-2007-0493: bind9 - Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a...
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
Scope: local
bookworm: resolved (fixed in 1:9.3.4-2)
bullseye: resolved (fixed in 1:9.3.4-2)
forky: resolved (fixed in 1:9.3.4-2)
sid: resolved (fixed in 1:9.3.4-2)
trixie: resolved (fixed in 1:9.3.4-2)
GHSA
GHSA-p6fj-c7mp-96mv: Use-after-free vulnerability in ISC BIND 9
ghsa_unreviewed·2022-05-01
CVE-2007-0493 [HIGH] GHSA-p6fj-c7mp-96mv: Use-after-free vulnerability in ISC BIND 9
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
OSV
CVE-2007-0493: Use-after-free vulnerability in ISC BIND 9
osv·2007-01-25·CVSS 7.8
CVE-2007-0493 [HIGH] CVE-2007-0493: Use-after-free vulnerability in ISC BIND 9
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
bugzilla·2007-04-27·CVSS 7.8
CVE-2007-0493 [HIGH] CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
Bugzilla
CVE-2007-0493 bind use-after-free
bugzilla·2007-02-25·CVSS 7.8
CVE-2007-0493 [HIGH] CVE-2007-0493 bind use-after-free
CVE-2007-0493 bind use-after-free
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to
9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows
remote attackers to cause a denial of service (named daemon crash) via
unspecified vectors that cause named to "dereference a freed fetch context."
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0057.html
Fedora
see https://bugzilla.redhat.com/show_bug.cgi?id=224443#c4
Bugzilla
CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
bugzilla·2007-01-25·CVSS 7.8
CVE-2007-0493 [HIGH] CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
+++ This bug was initially created as a clone of Bug #224443 +++
Description of problem:
fetchctx structures, not keeping count of its uses, might be read
even after beind deallocated resulting in name server denial of
service under certain circumstances.
Version-Release number of selected component (if applicable):
Unclear whether this issue also affects 3.2 BIND, besides 3.3.
For sure affects FC-5, FC-6 and RHEL-5
How reproducible:
Hardly ever.
Steps to Reproduce:
No known way to reproduce. The advisory notes, that the issue can be
partly mitigated by disabling recursion, so probably some deep recursive
queries might trigger the bug?
Actual results:
Server DoS?
Expected results:
What would you expect fr
Bugzilla
CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
bugzilla·2007-01-25·CVSS 7.8
CVE-2007-0493 [HIGH] CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
CVE-2007-0493 BIND might crash after attempting to read free()-ed memory
Description of problem:
fetchctx structures, not keeping count of its uses, might be read
even after beind deallocated resulting in name server denial of
service under certain circumstances.
Version-Release number of selected component (if applicable):
Unclear whether this issue also affects 3.2 BIND, besides 3.3.
For sure affects FC-5, FC-6 and RHEL-5
How reproducible:
Hardly ever.
Steps to Reproduce:
No known way to reproduce. The advisory notes, that the issue can be
partly mitigated by disabling recursion, so probably some deep recursive
queries might trigger the bug?
Actual results:
Server DoS?
Expected results:
What would you expect from read of deallocated memory? :)
Additional info:
ISC sucks at
http://docs.info.apple.com/article.html?artnum=305530http://fedoranews.org/cms/node/2507http://fedoranews.org/cms/node/2537http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.htmlhttp://marc.info/?l=bind-announce&m=116968519321296&w=2http://secunia.com/advisories/23904http://secunia.com/advisories/23924http://secunia.com/advisories/23943http://secunia.com/advisories/23972http://secunia.com/advisories/23974http://secunia.com/advisories/23977http://secunia.com/advisories/24014http://secunia.com/advisories/24048http://secunia.com/advisories/24054http://secunia.com/advisories/24129http://secunia.com/advisories/24203http://secunia.com/advisories/24930http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://secunia.com/advisories/25649http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.aschttp://security.gentoo.org/glsa/glsa-200702-06.xmlhttp://securitytracker.com/id?1017561http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.494157http://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4http://www.mandriva.com/security/advisories?name=MDKSA-2007:030http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0057.htmlhttp://www.securityfocus.com/archive/1/458066/100/0/threadedhttp://www.securityfocus.com/bid/22229http://www.trustix.org/errata/2007/0005http://www.ubuntu.com/usn/usn-418-1http://www.vupen.com/english/advisories/2007/0349http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939http://www.vupen.com/english/advisories/2007/2163http://www.vupen.com/english/advisories/2007/2315https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-989https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9614https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144http://docs.info.apple.com/article.html?artnum=305530http://fedoranews.org/cms/node/2507http://fedoranews.org/cms/node/2537http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.htmlhttp://marc.info/?l=bind-announce&m=116968519321296&w=2http://secunia.com/advisories/23904http://secunia.com/advisories/23924http://secunia.com/advisories/23943http://secunia.com/advisories/23972http://secunia.com/advisories/23974http://secunia.com/advisories/23977http://secunia.com/advisories/24014http://secunia.com/advisories/24048http://secunia.com/advisories/24054http://secunia.com/advisories/24129http://secunia.com/advisories/24203http://secunia.com/advisories/24930http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://secunia.com/advisories/25649http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.aschttp://security.gentoo.org/glsa/glsa-200702-06.xmlhttp://securitytracker.com/id?1017561http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.494157http://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4http://www.mandriva.com/security/advisories?name=MDKSA-2007:030http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0057.htmlhttp://www.securityfocus.com/archive/1/458066/100/0/threadedhttp://www.securityfocus.com/bid/22229http://www.trustix.org/errata/2007/0005http://www.ubuntu.com/usn/usn-418-1http://www.vupen.com/english/advisories/2007/0349http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939http://www.vupen.com/english/advisories/2007/2163http://www.vupen.com/english/advisories/2007/2315https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-989https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9614https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144
2007-01-25
Published