CVE-2007-2241
published 2007-05-02CVE-2007-2241: Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of…
PriorityP427high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
7.61%
93.9th percentile
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.4.1-1 (bookworm) | bind9 1:9.4.1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.4.1-1 | 1:9.4.1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-1 | 1:9.4.1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-1 | 1:9.4.1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-1 | 1:9.4.1-1 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1MEDIUM
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind remote DoS
vendor_redhat·2007-04-30·CVSS 7.1
CVE-2007-2241 [HIGH] bind remote DoS
bind remote DoS
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
Statement: Not vulnerable. These issues did not affect the versions of BIND as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2007-2241: bind9 - Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5....
vendor_debian·2007·CVSS 7.1
CVE-2007-2241 [HIGH] CVE-2007-2241: bind9 - Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5....
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
Scope: local
bookworm: resolved (fixed in 1:9.4.1-1)
bullseye: resolved (fixed in 1:9.4.1-1)
forky: resolved (fixed in 1:9.4.1-1)
sid: resolved (fixed in 1:9.4.1-1)
trixie: resolved (fixed in 1:9.4.1-1)
GHSA
GHSA-jw6v-3c7m-938x: Unspecified vulnerability in query
ghsa_unreviewed·2022-05-01
CVE-2007-2241 [HIGH] GHSA-jw6v-3c7m-938x: Unspecified vulnerability in query
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
OSV
CVE-2007-2241: Unspecified vulnerability in query
osv·2007-05-02·CVSS 7.1
CVE-2007-2241 [HIGH] CVE-2007-2241: Unspecified vulnerability in query
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
No detection rules found.
No public exploits indexed.
http://osvdb.org/34748http://secunia.com/advisories/25070http://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.kb.cert.org/vuls/id/718460http://www.mandriva.com/security/advisories?name=MDKSA-2007:100http://www.securityfocus.com/bid/23738http://www.securitytracker.com/id?1017985http://www.vupen.com/english/advisories/2007/1593https://exchange.xforce.ibmcloud.com/vulnerabilities/33988http://osvdb.org/34748http://secunia.com/advisories/25070http://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.kb.cert.org/vuls/id/718460http://www.mandriva.com/security/advisories?name=MDKSA-2007:100http://www.securityfocus.com/bid/23738http://www.securitytracker.com/id?1017985http://www.vupen.com/english/advisories/2007/1593https://exchange.xforce.ibmcloud.com/vulnerabilities/33988
2007-05-02
Published