PT-2007-3577 · Isc+1 · Isc Bind+1
Mark Andrews
·
Publicado
2007-05-02
·
Atualizado
2018-10-30
·
CVE-2007-2241
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ISC BIND versions 9.4.0, and 9.5.0a1 through 9.5.0a3
Description
The issue is related to an unspecified vulnerability in the query.c file of ISC BIND. When recursion is enabled, remote attackers can cause a denial of service by sending a sequence of queries that are processed by the
query addsoa function, leading to the daemon exiting.Recommendations
For ISC BIND version 9.4.0, update to a version that fixes this issue.
For ISC BIND versions 9.5.0a1 through 9.5.0a3, update to a version that fixes this issue.
As a temporary workaround, consider disabling recursion to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bind Server
Isc Bind