CVE-2007-0494: Medium severity ISC BIND vulnerability
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0494?
CVE-2007-0494 has a severity rating of medium as it can lead to a denial of service.
How do I fix CVE-2007-0494?
To fix CVE-2007-0494, you should upgrade to a patched version of ISC BIND, specifically version 9.2.8 or later.
What versions of ISC BIND are affected by CVE-2007-0494?
CVE-2007-0494 affects ISC BIND versions 9.0.x through 9.5.0a1, including various release candidates.
Can CVE-2007-0494 be exploited remotely?
Yes, CVE-2007-0494 can be exploited remotely by sending malicious ANY DNS query responses.
What impact does CVE-2007-0494 have on my system?
The impact of CVE-2007-0494 is that it can cause the BIND service to exit unexpectedly, resulting in downtime.