CVE-2007-0493

Description

Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to dereference a freed fetch context.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
13.838

Associated Vulnerability

VulnerabilityOS Platform
Update bind 9.5.0a1 to latest versionWindows
Multiple Vulnerabilities are affected in BIND 9.4.0Windows
Multiple Vulnerabilities are affected in BIND 9.3.0Windows
Multiple Vulnerabilities are affected in BIND 9.3.2Windows
Multiple Vulnerabilities are affected in BIND 9.3.1Windows
Multiple Vulnerabilities are affected in BIND 9.4.0.rc1Windows
Multiple Vulnerabilities are affected in BIND 9.5.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234