First published: Tue Jul 24 2007(Updated: )
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BIND 9 | =9.4.0 | |
BIND 9 | =9.4.1 | |
BIND 9 | =9.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2925 is regarded as a high-severity vulnerability due to its potential for remote exploitation.
To fix CVE-2007-2925, configure the access control lists in ISC BIND to properly set the allow-recursion and allow-query-cache options.
CVE-2007-2925 affects ISC BIND versions 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5.
The consequences of CVE-2007-2925 include unauthorized recursive queries and potential exposure of cached DNS data to remote attackers.
Yes, patches for CVE-2007-2925 are available in updated versions of ISC BIND beyond the affected versions.