PT-2007-3577 · Isc+1 · Isc Bind+1

Mark Andrews

·

Published

2007-05-02

·

Updated

2018-10-30

·

CVE-2007-2241

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ISC BIND versions 9.4.0, and 9.5.0a1 through 9.5.0a3
Description The issue is related to an unspecified vulnerability in the query.c file of ISC BIND. When recursion is enabled, remote attackers can cause a denial of service by sending a sequence of queries that are processed by the query addsoa function, leading to the daemon exiting.
Recommendations For ISC BIND version 9.4.0, update to a version that fixes this issue. For ISC BIND versions 9.5.0a1 through 9.5.0a3, update to a version that fixes this issue. As a temporary workaround, consider disabling recursion to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2241

Affected Products

Bind Server
Isc Bind