Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-0494 | First vendor Publication | 2007-01-25 |
Vendor | Cve | Last vendor Modification | 2017-10-11 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0494 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-19 | Data Handling |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:11523 | |||
Oval ID: | oval:org.mitre.oval:def:11523 | ||
Title: | ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability. | ||
Description: | ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2007-0494 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:21786 | |||
Oval ID: | oval:org.mitre.oval:def:21786 | ||
Title: | ELSA-2007:0057: bind security update (Moderate) | ||
Description: | ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2007:0057-02 CVE-2007-0493 CVE-2007-0494 | Version: | 13 |
Platform(s): | Oracle Linux 5 | Product(s): | bind |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-11-17 | Name : Mac OS X Version File : nvt/macosx_version.nasl |
2009-10-10 | Name : SLES9: Security update for bind File : nvt/sles9p5017734.nasl |
2009-05-05 | Name : HP-UX Update for BIND HPSBUX02219 File : nvt/gb_hp_ux_HPSBUX02219.nasl |
2009-04-09 | Name : Mandriva Update for bind MDKSA-2007:030 (bind) File : nvt/gb_mandriva_MDKSA_2007_030.nasl |
2009-03-23 | Name : Ubuntu Update for bind9 vulnerabilities USN-418-1 File : nvt/gb_ubuntu_USN_418_1.nasl |
2009-01-28 | Name : SuSE Update for bind SUSE-SA:2007:014 File : nvt/gb_suse_2007_014.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200702-06 (bind) File : nvt/glsa_200702_06.nasl |
2008-09-04 | Name : FreeBSD Ports: named File : nvt/freebsd_named.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1254-1 (bind9) File : nvt/deb_1254_1.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2007-026-01 bind File : nvt/esoft_slk_ssa_2007_026_01.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
31923 | ISC BIND Crafted ANY Request Response Multiple RRsets DoS |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | ISC BIND DNSSEC Validation Multiple RRsets DoS RuleID : 17680 - Revision : 10 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0057.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0044.nasl - Type : ACT_GATHER_INFO |
2013-03-13 | Name : The remote AIX host is missing a vendor-supplied security patch. File : aix_U800591.nasl - Type : ACT_GATHER_INFO |
2013-03-13 | Name : The remote AIX host is missing a vendor-supplied security patch. File : aix_U803849.nasl - Type : ACT_GATHER_INFO |
2013-03-13 | Name : The remote AIX host is missing a vendor-supplied security patch. File : aix_U804534.nasl - Type : ACT_GATHER_INFO |
2012-01-19 | Name : The remote name server may be affected by a denial of service vulnerability. File : bind9_dos4.nasl - Type : ACT_GATHER_INFO |
2009-07-27 | Name : The remote VMware ESX host is missing one or more security-related patches. File : vmware_VMSA-2007-0006.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-418-1.nasl - Type : ACT_GATHER_INFO |
2007-09-25 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHNE_35920.nasl - Type : ACT_GATHER_INFO |
2007-05-25 | Name : The remote host is missing a Mac OS X update that fixes several security issues. File : macosx_SecUpd2007-005.nasl - Type : ACT_GATHER_INFO |
2007-05-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0057.nasl - Type : ACT_GATHER_INFO |
2007-02-28 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_3cb6f059c69d11db9f82000e0c2e438a.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200702-06.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-030.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote host is missing a vendor-supplied security patch File : suse_SA_2007_014.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-026-01.nasl - Type : ACT_GATHER_INFO |
2007-02-09 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-147.nasl - Type : ACT_GATHER_INFO |
2007-02-09 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-164.nasl - Type : ACT_GATHER_INFO |
2007-02-09 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1254.nasl - Type : ACT_GATHER_INFO |
2007-02-09 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2007-0044.nasl - Type : ACT_GATHER_INFO |
2007-02-09 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0044.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-02-02 01:05:52 |
|
2024-02-01 12:02:10 |
|
2023-09-05 12:05:29 |
|
2023-09-05 01:02:01 |
|
2023-09-02 12:05:34 |
|
2023-09-02 01:02:02 |
|
2023-08-12 12:06:31 |
|
2023-08-12 01:02:02 |
|
2023-08-11 12:05:38 |
|
2023-08-11 01:02:05 |
|
2023-08-06 12:05:21 |
|
2023-08-06 01:02:02 |
|
2023-08-04 12:05:27 |
|
2023-08-04 01:02:06 |
|
2023-07-14 12:05:26 |
|
2023-07-14 01:02:03 |
|
2023-03-29 01:06:03 |
|
2023-03-28 12:02:08 |
|
2022-10-11 12:04:48 |
|
2022-10-11 01:01:54 |
|
2021-05-04 12:05:18 |
|
2021-04-22 01:05:52 |
|
2020-05-23 00:19:11 |
|
2019-03-19 12:02:20 |
|
2017-10-11 09:23:50 |
|
2017-07-29 12:01:59 |
|
2016-12-07 09:24:09 |
|
2016-10-18 12:02:14 |
|
2016-08-20 09:22:27 |
|
2016-04-04 21:25:22 |
|
2014-02-17 10:38:50 |
|
2014-01-19 21:23:52 |
|
2013-05-11 10:18:31 |
|