Overview
ISC (Internet Systems Consortiuim) BIND fails to properly set default access control lists. This may allow unauthorized users to make recursive querries and querry the cache.
Description
From the ISC BIND security page: The default access control lists (acls) are not being correctly set. If not set anyone can make recursive queries and/or query the cache contents. |
Impact
A remote, unauthenticated attacker may be able to cause a vulnerable DNS server perform recursion. This could be used to perform denial-of-service attacks. An attacker may also be able to querry the cache. |
Solution
Upgrade or Patch |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to ISC for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-2925 |
Severity Metric: | 16.98 |
Date Public: | 2007-07-24 |
Date First Published: | 2007-07-27 |
Date Last Updated: | 2008-06-04 21:39 UTC |
Document Revision: | 26 |