CVE-2007-0494
published 2007-01-25CVE-2007-0494: ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
43.35%
98.6th percentile
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.3.4-2 (bookworm) | bind9 1:9.3.4-2 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.3.4-2 | 1:9.3.4-2 |
| isc | bind9 | >= 0 < 1:9.3.4-2 | 1:9.3.4-2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-07:02.bind: Multiple Denial of Service vulnerabilities in named(8)
bsd_advisories·2007-02-09·CVSS 7.8
CVE-2007-0493 [HIGH] FreeBSD-SA-07:02.bind: Multiple Denial of Service vulnerabilities in named(8)
FreeBSD-SA-07:02.bind Security Advisory
The FreeBSD Project
Topic: Multiple Denial of Service vulnerabilities in named(8)
Category: contrib
Module: bind
Announced: 2007-02-09
Affects: FreeBSD 5.3 and later.
Corrected: 2007-02-07 00:42:09 UTC (RELENG_6, 6.2-STABLE)
2007-02-09 20:24:15 UTC (RELENG_6_2, 6.2-RELEASE-p1)
2007-02-09 20:23:29 UTC (RELENG_6_1, 6.1-RELEASE-p13)
2007-02-07 00:46:35 UTC (RELENG_5, 5.5-STABLE)
2007-02-09 20:22:44 UTC (RELENG_5_5, 5.5-RELEASE-p11)
CVE Name: CVE-2007-0493, CVE-2007-0494
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Int
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2007-02-06
CVE-2007-0493 Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Bind vulnerabilities
A flaw was discovered in Bind's DNSSEC validation code. Remote
attackers could send a specially crafted DNS query which would cause the
Bind server to crash, resulting in a denial of service. Only servers
configured to use DNSSEC extensions were vulnerable.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
BIND dnssec denial of service
vendor_redhat·2007-01-25·CVSS 4.3
CVE-2007-0494 [MEDIUM] BIND dnssec denial of service
BIND dnssec denial of service
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
Debian
CVE-2007-0494: bind9 - ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0...
vendor_debian·2007·CVSS 4.3
CVE-2007-0494 [MEDIUM] CVE-2007-0494: bind9 - ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0...
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
Scope: local
bookworm: resolved (fixed in 1:9.3.4-2)
bullseye: resolved (fixed in 1:9.3.4-2)
forky: resolved (fixed in 1:9.3.4-2)
sid: resolved (fixed in 1:9.3.4-2)
trixie: resolved (fixed in 1:9.3.4-2)
GHSA
GHSA-vhvp-gwh8-h6v7: ISC BIND 9
ghsa_unreviewed·2022-05-03
CVE-2007-0494 [MEDIUM] GHSA-vhvp-gwh8-h6v7: ISC BIND 9
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
OSV
CVE-2007-0494: ISC BIND 9
osv·2007-01-25·CVSS 4.3
CVE-2007-0494 [MEDIUM] CVE-2007-0494: ISC BIND 9
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2022 kdebase3 flash-player interaction problem
bugzilla·2007-06-10·CVSS 6.8
CVE-2007-2022 [MEDIUM] CVE-2007-2022 kdebase3 flash-player interaction problem
CVE-2007-2022 kdebase3 flash-player interaction problem
According to
http://www.novell.com/linux/security/advisories/2007_12_sr.html
A problem with the interaction between the Flash Player and the Konqueror web
browser was fixed. The problem could lead to key presses leaking to the applet
instead of the browser. (CVE-2007-2022)
Patch from Dirk Mueller.
Discussion:
Created attachment 156673
proposed patch
---
See also
http://www.adobe.com/support/security/advisories/apsa07-03.html
Setting impact=important
---
it's fixed in
---
This issue has been addressed in following products:
Red Hat Linux Enterprise 3
Red Hat Linux Enterprise 4
Red Hat Linux Enterprise 4.5.z
Red Hat Linux Enterprise 5
Via RHSA-2007:0494, https://rhn.redhat.com/errata/RHSA-2007-0494.html
Bugzilla
CVE-2007-0494 BIND dnssec denial of service
bugzilla·2007-01-30·CVSS 4.3
CVE-2007-0494 [MEDIUM] CVE-2007-0494 BIND dnssec denial of service
CVE-2007-0494 BIND dnssec denial of service
+++ This bug was initially created as a clone of Bug #225222 +++
ISC has reported a bug in BIND which could cause a server using dnssec
validation to crash when processing a type * (ANY) DNS query response that
contains multiple RRsets.
This flaw should also affects RHEL 2 and 3.
Discussion:
*** This bug has been marked as a duplicate of 225268 ***
Bugzilla
CVE-2007-0494 BIND dnssec denial of service
bugzilla·2007-01-29·CVSS 4.3
CVE-2007-0494 [MEDIUM] CVE-2007-0494 BIND dnssec denial of service
CVE-2007-0494 BIND dnssec denial of service
ISC has reported a bug in BIND which could cause a server using dnssec
validation to crash when processing a type * (ANY) DNS query response that
contains multiple RRsets.
This flaw should also affects RHEL 2 and 3.
Discussion:
*** Bug 227468 has been marked as a duplicate of this bug. ***
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2007-0044.html
Bugzilla
CVE-2007-0494 BIND dnssec denial of service
bugzilla·2007-01-29·CVSS 4.3
CVE-2007-0494 [MEDIUM] CVE-2007-0494 BIND dnssec denial of service
CVE-2007-0494 BIND dnssec denial of service
+++ This bug was initially created as a clone of Bug #225222 +++
ISC has reported a bug in BIND which could cause a server using dnssec
validation to crash when processing a type * (ANY) DNS query response that
contains multiple RRsets.
An FC6 update has already been released for this flaw.
Discussion:
*** Bug 225397 has been marked as a duplicate of this bug. ***
Bugzilla
CVE-2007-0494 BIND dnssec denial of service
bugzilla·2007-01-29·CVSS 4.3
CVE-2007-0494 [MEDIUM] CVE-2007-0494 BIND dnssec denial of service
CVE-2007-0494 BIND dnssec denial of service
+++ This bug was initially created as a clone of Bug #225222 +++
ISC has reported a bug in BIND which could cause a server using dnssec
validation to crash when processing a type * (ANY) DNS query response that
contains multiple RRsets.
Discussion:
Created attachment 147022
proposed fix
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2007-0057.html
---
*** Bug 231003 has been marked as a duplicate of this bug. ***
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://docs.info.apple.com/article.html?artnum=305530http://fedoranews.org/cms/node/2507http://fedoranews.org/cms/node/2537http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.htmlhttp://marc.info/?l=bind-announce&m=116968519300764&w=2http://secunia.com/advisories/23904http://secunia.com/advisories/23924http://secunia.com/advisories/23943http://secunia.com/advisories/23944http://secunia.com/advisories/23972http://secunia.com/advisories/23974http://secunia.com/advisories/23977http://secunia.com/advisories/24014http://secunia.com/advisories/24048http://secunia.com/advisories/24054http://secunia.com/advisories/24083http://secunia.com/advisories/24129http://secunia.com/advisories/24203http://secunia.com/advisories/24284http://secunia.com/advisories/24648http://secunia.com/advisories/24930http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://secunia.com/advisories/25482http://secunia.com/advisories/25649http://secunia.com/advisories/25715http://secunia.com/advisories/26909http://secunia.com/advisories/27706http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.aschttp://security.gentoo.org/glsa/glsa-200702-06.xmlhttp://securitytracker.com/id?1017573http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.494157http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1http://support.avaya.com/elmodocs2/security/ASA-2007-125.htmhttp://www-1.ibm.com/support/docview.wss?uid=isg1IY95618http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324http://www.debian.org/security/2007/dsa-1254http://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4http://www.mandriva.com/security/advisories?name=MDKSA-2007:030http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0044.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0057.htmlhttp://www.securityfocus.com/bid/22231http://www.trustix.org/errata/2007/0005http://www.ubuntu.com/usn/usn-418-1http://www.vupen.com/english/advisories/2007/1401http://www.vupen.com/english/advisories/2007/1939http://www.vupen.com/english/advisories/2007/2002http://www.vupen.com/english/advisories/2007/2163http://www.vupen.com/english/advisories/2007/2245http://www.vupen.com/english/advisories/2007/2315http://www.vupen.com/english/advisories/2007/3229https://exchange.xforce.ibmcloud.com/vulnerabilities/31838https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488https://issues.rpath.com/browse/RPL-989https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11523https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://docs.info.apple.com/article.html?artnum=305530http://fedoranews.org/cms/node/2507http://fedoranews.org/cms/node/2537http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.htmlhttp://marc.info/?l=bind-announce&m=116968519300764&w=2http://secunia.com/advisories/23904http://secunia.com/advisories/23924http://secunia.com/advisories/23943http://secunia.com/advisories/23944http://secunia.com/advisories/23972http://secunia.com/advisories/23974http://secunia.com/advisories/23977http://secunia.com/advisories/24014http://secunia.com/advisories/24048http://secunia.com/advisories/24054http://secunia.com/advisories/24083http://secunia.com/advisories/24129http://secunia.com/advisories/24203http://secunia.com/advisories/24284http://secunia.com/advisories/24648http://secunia.com/advisories/24930http://secunia.com/advisories/24950http://secunia.com/advisories/25402http://secunia.com/advisories/25482http://secunia.com/advisories/25649http://secunia.com/advisories/25715http://secunia.com/advisories/26909http://secunia.com/advisories/27706http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc
+ 32 more references
2007-01-25
Published