« Volver al listado

CVE-2007-2925

Estado: ModificadaMedia (5.8)—

The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2925",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-07-24T17:30:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/26227",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/26236",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/26509",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/26515",
      "source": "cret@cert.org"
    },
    {
      "url": "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=623903",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200708-13.xml",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:149",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.022.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/25076",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1018441",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.521385",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2628",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2914",
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35571",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/26227",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26236",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26509",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26515",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=623903",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200708-13.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.isc.org/index.pl?/sw/bind/bind-security.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:149",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.022.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/25076",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1018441",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.521385",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2628",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2914",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35571",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache."
    },
    {
      "lang": "es",
      "value": "La lista de control de acceso por defecto (ACL) en ISC BIND 9.4.0, 9.4.1, y 9.5.0a1 hasta 9.5.0a5 no asigna las ACLs allow-recursion y allow-query-cache, lo cual permite a atacantes remotos realizar consultas recursivas y consultar la cache."
    }
  ],
  "lastModified": "2026-06-16T22:40:42.637",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:isc:bind:9.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D7C7524-6943-4D94-8835-0221F0F0CD63"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "916D4013-27A5-4688-A985-A9B77F90AC45"
            },
            {
              "criteria": "cpe:2.3:a:isc:bind:9.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32CEF8AD-9EE7-4ADA-888E-883751962529"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Not vulnerable. This issu did not affect the versions of bind as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.",
      "lastModified": "2007-07-26T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}