PT-2007-3577 · Isc+1 · Isc Bind+1

Mark Andrews

·

Publicado

2007-05-02

·

Atualizado

2018-10-30

·

CVE-2007-2241

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC BIND versions 9.4.0, and 9.5.0a1 through 9.5.0a3
Description The issue is related to an unspecified vulnerability in the query.c file of ISC BIND. When recursion is enabled, remote attackers can cause a denial of service by sending a sequence of queries that are processed by the query addsoa function, leading to the daemon exiting.
Recommendations For ISC BIND version 9.4.0, update to a version that fixes this issue. For ISC BIND versions 9.5.0a1 through 9.5.0a3, update to a version that fixes this issue. As a temporary workaround, consider disabling recursion to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2241

Produtos afetados

Bind Server
Isc Bind