CVE-2007-2925
published 2007-07-24CVE-2007-2925: The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which…
PriorityP432medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
6.20%
92.8th percentile
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.4.1-P1-1 (bookworm) | bind9 1:9.4.1-P1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
| isc | bind9 | >= 0 < 1:9.4.1-P1-1 | 1:9.4.1-P1-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind allow-query-cache/allow-recursion default ACL issue
vendor_redhat·2007-07-23·CVSS 5.8
CVE-2007-2925 [MEDIUM] bind allow-query-cache/allow-recursion default ACL issue
bind allow-query-cache/allow-recursion default ACL issue
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
Statement: Not vulnerable. This issu did not affect the versions of bind as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2007-2925: bind9 - The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 thr...
vendor_debian·2007·CVSS 5.8
CVE-2007-2925 [MEDIUM] CVE-2007-2925: bind9 - The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 thr...
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
Scope: local
bookworm: resolved (fixed in 1:9.4.1-P1-1)
bullseye: resolved (fixed in 1:9.4.1-P1-1)
forky: resolved (fixed in 1:9.4.1-P1-1)
sid: resolved (fixed in 1:9.4.1-P1-1)
trixie: resolved (fixed in 1:9.4.1-P1-1)
GHSA
GHSA-439f-hv4q-rmc5: The default access control lists (ACL) in ISC BIND 9
ghsa_unreviewed·2022-05-01
CVE-2007-2925 [MEDIUM] GHSA-439f-hv4q-rmc5: The default access control lists (ACL) in ISC BIND 9
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
OSV
CVE-2007-2925: The default access control lists (ACL) in ISC BIND 9
osv·2007-07-24·CVSS 5.8
CVE-2007-2925 [MEDIUM] CVE-2007-2925: The default access control lists (ACL) in ISC BIND 9
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
No detection rules found.
No public exploits indexed.
CWE
Improper Authorization
mitre_cwe
CWE-285 Improper Authorization
CWE-285: Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Background: An access control list (ACL) represents who/what has permissions to a given object. Different operating systems implement (ACLs) in different ways. In UNIX, there are three types of permissions: read, write, and execute. Users are divided into three classes for file access: owner, group owner, and all other users where each class has a separate set of rights. In Windows NT, there are four basic types of permissions for files: "No access", "Read access", "Change access", and "Full control". Windows NT extends the concept of three types of users in UNIX to include a list of users and groups along with their
CWE
Missing Authorization
mitre_cwe
CWE-862 Missing Authorization
CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Background: An access control list (ACL) represents who/what has permissions to a given object. Different operating systems implement (ACLs) in different ways. In UNIX, there are three types of permissions: read, write, and execute. Users are divided into three classes for file access: owner, group owner, and all other users where each class has a separate set of rights. In Windows NT, there are four basic types of permissions for files: "No access", "Read access", "Change access", and "Full control". Windows NT extends the concept of three types of users in UNIX to include a list of users and groups along with their associated permissions.
http://secunia.com/advisories/26227http://secunia.com/advisories/26236http://secunia.com/advisories/26509http://secunia.com/advisories/26515http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=623903http://www.gentoo.org/security/en/glsa/glsa-200708-13.xmlhttp://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.mandriva.com/security/advisories?name=MDKSA-2007:149http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.022.htmlhttp://www.securityfocus.com/bid/25076http://www.securitytracker.com/id?1018441http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.521385http://www.vupen.com/english/advisories/2007/2628http://www.vupen.com/english/advisories/2007/2914https://exchange.xforce.ibmcloud.com/vulnerabilities/35571http://secunia.com/advisories/26227http://secunia.com/advisories/26236http://secunia.com/advisories/26509http://secunia.com/advisories/26515http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=623903http://www.gentoo.org/security/en/glsa/glsa-200708-13.xmlhttp://www.isc.org/index.pl?/sw/bind/bind-security.phphttp://www.mandriva.com/security/advisories?name=MDKSA-2007:149http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.022.htmlhttp://www.securityfocus.com/bid/25076http://www.securitytracker.com/id?1018441http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.521385http://www.vupen.com/english/advisories/2007/2628http://www.vupen.com/english/advisories/2007/2914https://exchange.xforce.ibmcloud.com/vulnerabilities/35571
2007-07-24
Published