CVE-2007-2925: Medium severity ISC BIND vulnerability
The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2925?
CVE-2007-2925 is regarded as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2007-2925?
To fix CVE-2007-2925, configure the access control lists in ISC BIND to properly set the allow-recursion and allow-query-cache options.
What systems are affected by CVE-2007-2925?
CVE-2007-2925 affects ISC BIND versions 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5.
What are the potential consequences of CVE-2007-2925?
The consequences of CVE-2007-2925 include unauthorized recursive queries and potential exposure of cached DNS data to remote attackers.
Is there a patch available for CVE-2007-2925?
Yes, patches for CVE-2007-2925 are available in updated versions of ISC BIND beyond the affected versions.