CVE-2007-0493
Last modified
CVE-2007-0493 is a vulnerability of currently unknown severity. Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context.". EPSS estimates a 12.08% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Isc | Bind | 9.3.0 |
| Isc | Bind | 9.3.1 |
| Isc | Bind | 9.3.2 |
| Isc | Bind | 9.4.0 |
| Isc | Bind | 9.5.0 |
References
- http://secunia.com/advisories/23904Vendor Advisory
- http://secunia.com/advisories/23904Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0493?
How severe is CVE-2007-0493?
How do I fix CVE-2007-0493?
Are you affected by CVE-2007-0493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
