CVE-2007-0494
Summary
| CVE | CVE-2007-0494 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-25 20:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Isc | Bind | 9.0 | All | All | All |
| Application | Isc | Bind | 9.0.0 | rc1 | All | All |
| Application | Isc | Bind | 9.0.0 | rc2 | All | All |
| Application | Isc | Bind | 9.0.0 | rc3 | All | All |
| Application | Isc | Bind | 9.0.0 | rc4 | All | All |
| Application | Isc | Bind | 9.0.0 | rc5 | All | All |
| Application | Isc | Bind | 9.0.0 | rc6 | All | All |
| Application | Isc | Bind | 9.0.1 | All | All | All |
| Application | Isc | Bind | 9.0.1 | rc1 | All | All |
| Application | Isc | Bind | 9.0.1 | rc2 | All | All |
| Application | Isc | Bind | 9.1 | All | All | All |
| Application | Isc | Bind | 9.1.0 | rc1 | All | All |
| Application | Isc | Bind | 9.1.1 | All | All | All |
| Application | Isc | Bind | 9.1.1 | rc1 | All | All |
| Application | Isc | Bind | 9.1.1 | rc2 | All | All |
| Application | Isc | Bind | 9.1.1 | rc3 | All | All |
| Application | Isc | Bind | 9.1.1 | rc4 | All | All |
| Application | Isc | Bind | 9.1.1 | rc5 | All | All |
| Application | Isc | Bind | 9.1.1 | rc6 | All | All |
| Application | Isc | Bind | 9.1.1 | rc7 | All | All |
| Application | Isc | Bind | 9.1.2 | All | All | All |
| Application | Isc | Bind | 9.1.2 | rc1 | All | All |
| Application | Isc | Bind | 9.1.3 | All | All | All |
| Application | Isc | Bind | 9.1.3 | rc1 | All | All |
| Application | Isc | Bind | 9.1.3 | rc2 | All | All |
| Application | Isc | Bind | 9.1.3 | rc3 | All | All |
| Application | Isc | Bind | 9.2 | All | All | All |
| Application | Isc | Bind | 9.2.0 | All | All | All |
| Application | Isc | Bind | 9.2.0 | a1 | All | All |
| Application | Isc | Bind | 9.2.0 | a2 | All | All |
| Application | Isc | Bind | 9.2.0 | a3 | All | All |
| Application | Isc | Bind | 9.2.0 | b1 | All | All |
| Application | Isc | Bind | 9.2.0 | b2 | All | All |
| Application | Isc | Bind | 9.2.0 | rc1 | All | All |
| Application | Isc | Bind | 9.2.0 | rc10 | All | All |
| Application | Isc | Bind | 9.2.0 | rc2 | All | All |
| Application | Isc | Bind | 9.2.0 | rc3 | All | All |
| Application | Isc | Bind | 9.2.0 | rc4 | All | All |
| Application | Isc | Bind | 9.2.0 | rc5 | All | All |
| Application | Isc | Bind | 9.2.0 | rc6 | All | All |
| Application | Isc | Bind | 9.2.0 | rc7 | All | All |
| Application | Isc | Bind | 9.2.0 | rc8 | All | All |
| Application | Isc | Bind | 9.2.0 | rc9 | All | All |
| Application | Isc | Bind | 9.2.1 | All | All | All |
| Application | Isc | Bind | 9.2.1 | rc1 | All | All |
| Application | Isc | Bind | 9.2.1 | rc2 | All | All |
| Application | Isc | Bind | 9.2.2 | All | All | All |
| Application | Isc | Bind | 9.2.2 | p2 | All | All |
| Application | Isc | Bind | 9.2.2 | p3 | All | All |
| Application | Isc | Bind | 9.2.2 | rc1 | All | All |
| Application | Isc | Bind | 9.2.3 | All | All | All |
| Application | Isc | Bind | 9.2.3 | rc1 | All | All |
| Application | Isc | Bind | 9.2.3 | rc2 | All | All |
| Application | Isc | Bind | 9.2.3 | rc3 | All | All |
| Application | Isc | Bind | 9.2.3 | rc4 | All | All |
| Application | Isc | Bind | 9.2.4 | All | All | All |
| Application | Isc | Bind | 9.2.4 | rc2 | All | All |
| Application | Isc | Bind | 9.2.4 | rc3 | All | All |
| Application | Isc | Bind | 9.2.4 | rc4 | All | All |
| Application | Isc | Bind | 9.2.4 | rc5 | All | All |
| Application | Isc | Bind | 9.2.4 | rc6 | All | All |
| Application | Isc | Bind | 9.2.4 | rc7 | All | All |
| Application | Isc | Bind | 9.2.4 | rc8 | All | All |
| Application | Isc | Bind | 9.2.5 | All | All | All |
| Application | Isc | Bind | 9.2.5 | b2 | All | All |
| Application | Isc | Bind | 9.2.5 | rc1 | All | All |
| Application | Isc | Bind | 9.2.6 | All | All | All |
| Application | Isc | Bind | 9.2.6 | rc1 | All | All |
| Application | Isc | Bind | 9.3 | All | All | All |
| Application | Isc | Bind | 9.3.0 | All | All | All |
| Application | Isc | Bind | 9.3.0 | b2 | All | All |
| Application | Isc | Bind | 9.3.0 | b3 | All | All |
| Application | Isc | Bind | 9.3.0 | b4 | All | All |
| Application | Isc | Bind | 9.3.0 | rc1 | All | All |
| Application | Isc | Bind | 9.3.0 | rc2 | All | All |
| Application | Isc | Bind | 9.3.0 | rc3 | All | All |
| Application | Isc | Bind | 9.3.0 | rc4 | All | All |
| Application | Isc | Bind | 9.3.1 | All | All | All |
| Application | Isc | Bind | 9.3.1 | b2 | All | All |
| Application | Isc | Bind | 9.3.1 | rc1 | All | All |
| Application | Isc | Bind | 9.3.2 | All | All | All |
| Application | Isc | Bind | 9.3.2 | rc1 | All | All |
| Application | Isc | Bind | 9.4.0 | a1 | All | All |
| Application | Isc | Bind | 9.4.0 | a2 | All | All |
| Application | Isc | Bind | 9.4.0 | a3 | All | All |
| Application | Isc | Bind | 9.4.0 | a4 | All | All |
| Application | Isc | Bind | 9.4.0 | a5 | All | All |
| Application | Isc | Bind | 9.4.0 | b1 | All | All |
| Application | Isc | Bind | 9.4.0 | b2 | All | All |
| Application | Isc | Bind | 9.4.0 | b3 | All | All |
| Application | Isc | Bind | 9.4.0 | rc1 | All | All |
| Application | Isc | Bind | 9.5.0 | a1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc | af854a3a-2127-422b-91ae-364da2661108 | security.freebsd.org | |
| Sun Solaris 10 BIND DNSSEC Denial of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 'Internet Systems Consortium Security Advisory.' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| OpenPKG Corporation: Security: Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.openpkg.com | |
| Red Hat update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ISC has a new website | Internet Systems Consortium | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | Patch |
| issues.rpath.com/browse/RPL-989 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| [SECURITY] Fedora Core 6 Update: bind-9.3.4-1.fc6 | FedoraNEWS.ORG | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| www2.itrc.hp.com/service/cki/docDisplay.do | af854a3a-2127-422b-91ae-364da2661108 | www2.itrc.hp.com | |
| ISC has a new website | Internet Systems Consortium | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | |
| VMware ESX Server Multiple Security Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| [Full-Disclosure] Mailing List Charter | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| USN-418-1: Bind vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Mandriva update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20564.www2.hpe.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| HP-UX update for Bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Ubuntu update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| About Security Update 2007-005 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Fedora update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| FreeBSD update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo update for vmware - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1254-1 bind9 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Slackware update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ISC BIND Denial of Service Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SGI Advanced Linux Environment 3 Multiple Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| #200061: Security Vulnerability in Solaris 10 BIND DNSSEC May Cause a Denial of Service | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| rPath update for bind and bind-utils - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| APPLE-SA-2007-05-24 Security Update 2007-005 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| ISC has a new website | Internet Systems Consortium | af854a3a-2127-422b-91ae-364da2661108 | www.isc.org | Patch |
| ASA-2007-125 (RHSA-2007-0044) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Debian update for bind9 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM AIX BIND Denial of Service Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| patches.sgi.com/support/free/security/advisories/20070201-01-P.asc | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Trustix update for bind and ed - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Avaya Products bind Denial of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora Core 5 Update: bind-9.3.4-1.fc5 | FedoraNEWS.ORG | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| HP Insight Management Agents SSL Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: bind remote denial of service (SUSE-SA:2007:014) | af854a3a-2127-422b-91ae-364da2661108 | lists.suse.com | |
| SecurityTracker.com Archives - BIND DNSSEC Validation Bug Lets Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| HP Tru64 UNIX Multiple SSL and BIND Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Apple Mac OS X Security Update for Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.trustix.org/errata/2007/0005 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| SUSE update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Fedora update for bind - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Linux Documentation -- BIND: Denial of Service | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.