CVE-2007-0494

Publication date 25 January 2007

Last updated 24 July 2024


Ubuntu priority

ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.

Status

Package Ubuntu Release Status
bind9 7.04 feisty
Fixed 9.3.4-2ubuntu2.1
6.10 edgy
Fixed 9.3.2-2ubuntu3.2
6.06 LTS dapper
Fixed 9.3.2-2ubuntu1.3

References

Related Ubuntu Security Notices (USN)

    • USN-418-1
    • Bind vulnerabilities
    • 6 February 2007

Other references