Lucene search

K
cve[email protected]CVE-2007-0493
HistoryJan 25, 2007 - 8:28 p.m.

CVE-2007-0493

2007-01-2520:28:00
web.nvd.nist.gov
42
cve-2007-0493
isc
bind
vulnerability
denial of service
remote attack

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.2 High

AI Score

Confidence

High

0.223 Low

EPSS

Percentile

96.5%

Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to “dereference a freed fetch context.”

Affected configurations

NVD
Node
iscbindMatch9.3.0
OR
iscbindMatch9.3.1
OR
iscbindMatch9.3.2
OR
iscbindMatch9.4.0
OR
iscbindMatch9.4.0rc1
OR
iscbindMatch9.5.0

References

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.2 High

AI Score

Confidence

High

0.223 Low

EPSS

Percentile

96.5%