CVE-2007-0494
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 43%
exploitation probability
43%top 1% of all CVEs
observed exploitation
nono source reports it
ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
Affected products
n/a · n/aReferences
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://docs.info.apple.com/article.html?artnum=305530http://fedoranews.org/cms/node/2507http://fedoranews.org/cms/node/2537http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.htmlhttp://marc.info/?l=bind-announce&m=116968519300764&w=2http://secunia.com/advisories/23904http://secunia.com/advisories/23924