CVE-2007-0493: Use After Free
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0493?
The severity of CVE-2007-0493 is classified as high due to its potential to cause denial of service through a crash of the named daemon.
What versions of ISC BIND are affected by CVE-2007-0493?
ISC BIND versions 9.3.0 to 9.3.3, 9.4.0a1 to 9.4.0a6, 9.4.0b1 to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 are affected by CVE-2007-0493.
How do I fix CVE-2007-0493?
To fix CVE-2007-0493, update to a patched version of ISC BIND, specifically versions 9.3.4 or later.
What type of attack is possible with CVE-2007-0493?
CVE-2007-0493 enables remote attackers to perform a denial of service attack that crashes the named daemon.
How does CVE-2007-0493 exploit the ISC BIND server?
CVE-2007-0493 exploits a use-after-free vulnerability that occurs when named dereferences a freed fetch context.