CVE-2007-0494

ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.

Published: 2007-01-25 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2007-0494 is rated Moderate Risk (47.2/100): CVSS Medium severity, with high exploitation likelihood (EPSS 41.54%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2007-0494

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-05 45.60% 41.54% -4.06%
2 2025-09-13 44.73% 45.60% +0.87%
3 2025-07-22 44.73%

Full EPSS history (15 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2007-0494

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2007-0494

OS Trackers for CVE-2007-0494

vendor priority summary link
debian medium CVE-2007-0494 medium priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2007-0494
gentoo normal CVE-2007-0494: 1 GLSA(s) (200702-06), 1 atom(s) (net-dns/bind); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2007-0494
redhat medium https://access.redhat.com/security/cve/CVE-2007-0494
ubuntu medium CVE-2007-0494 medium priority: Ubuntu including 1 source packages (bind9), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 3, needs-triage 1. https://ubuntu.com/security/CVE-2007-0494

NVD evaluator notes for CVE-2007-0494

Solution: Syccessful exploitation requires that the victim has enabled dnssec validation in named.conf by specifying trusted-keys.

Affected software / configurations for CVE-2007-0494

Vendor Product Version Raw CPE
isc bind 9.0 cpe:2.3:a:isc:bind:9.0:*:*:*:*:*:*:*
isc bind 9.0.0 cpe:2.3:a:isc:bind:9.0.0:rc1:*:*:*:*:*:*
isc bind 9.0.0 cpe:2.3:a:isc:bind:9.0.0:rc2:*:*:*:*:*:*
isc bind 9.0.0 cpe:2.3:a:isc:bind:9.0.0:rc3:*:*:*:*:*:*
isc bind 9.0.0 cpe:2.3:a:isc:bind:9.0.0:rc4:*:*:*:*:*:*
isc bind 9.0.0 cpe:2.3:a:isc:bind:9.0.0:rc5:*:*:*:*:*:*
isc bind 9.0.0 cpe:2.3:a:isc:bind:9.0.0:rc6:*:*:*:*:*:*
isc bind 9.0.1 cpe:2.3:a:isc:bind:9.0.1:*:*:*:*:*:*:*
isc bind 9.0.1 cpe:2.3:a:isc:bind:9.0.1:rc1:*:*:*:*:*:*
isc bind 9.0.1 cpe:2.3:a:isc:bind:9.0.1:rc2:*:*:*:*:*:*
isc bind 9.1 cpe:2.3:a:isc:bind:9.1:*:*:*:*:*:*:*
isc bind 9.1.0 cpe:2.3:a:isc:bind:9.1.0:rc1:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:*:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc1:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc2:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc3:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc4:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc5:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc6:*:*:*:*:*:*
isc bind 9.1.1 cpe:2.3:a:isc:bind:9.1.1:rc7:*:*:*:*:*:*
isc bind 9.1.2 cpe:2.3:a:isc:bind:9.1.2:*:*:*:*:*:*:*
isc bind 9.1.2 cpe:2.3:a:isc:bind:9.1.2:rc1:*:*:*:*:*:*
isc bind 9.1.3 cpe:2.3:a:isc:bind:9.1.3:*:*:*:*:*:*:*
isc bind 9.1.3 cpe:2.3:a:isc:bind:9.1.3:rc1:*:*:*:*:*:*
isc bind 9.1.3 cpe:2.3:a:isc:bind:9.1.3:rc2:*:*:*:*:*:*
isc bind 9.1.3 cpe:2.3:a:isc:bind:9.1.3:rc3:*:*:*:*:*:*
isc bind 9.2 cpe:2.3:a:isc:bind:9.2:*:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:*:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:a1:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:a2:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:a3:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:b1:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:b2:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc1:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc10:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc2:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc3:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc4:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc5:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc6:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc7:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc8:*:*:*:*:*:*
isc bind 9.2.0 cpe:2.3:a:isc:bind:9.2.0:rc9:*:*:*:*:*:*
isc bind 9.2.1 cpe:2.3:a:isc:bind:9.2.1:*:*:*:*:*:*:*
isc bind 9.2.1 cpe:2.3:a:isc:bind:9.2.1:rc1:*:*:*:*:*:*
isc bind 9.2.1 cpe:2.3:a:isc:bind:9.2.1:rc2:*:*:*:*:*:*
isc bind 9.2.2 cpe:2.3:a:isc:bind:9.2.2:*:*:*:*:*:*:*
isc bind 9.2.2 cpe:2.3:a:isc:bind:9.2.2:p2:*:*:*:*:*:*
isc bind 9.2.2 cpe:2.3:a:isc:bind:9.2.2:p3:*:*:*:*:*:*
isc bind 9.2.2 cpe:2.3:a:isc:bind:9.2.2:rc1:*:*:*:*:*:*
isc bind 9.2.3 cpe:2.3:a:isc:bind:9.2.3:*:*:*:*:*:*:*
isc bind 9.2.3 cpe:2.3:a:isc:bind:9.2.3:rc1:*:*:*:*:*:*
isc bind 9.2.3 cpe:2.3:a:isc:bind:9.2.3:rc2:*:*:*:*:*:*
isc bind 9.2.3 cpe:2.3:a:isc:bind:9.2.3:rc3:*:*:*:*:*:*
isc bind 9.2.3 cpe:2.3:a:isc:bind:9.2.3:rc4:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:*:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc2:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc3:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc4:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc5:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc6:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc7:*:*:*:*:*:*
isc bind 9.2.4 cpe:2.3:a:isc:bind:9.2.4:rc8:*:*:*:*:*:*
isc bind 9.2.5 cpe:2.3:a:isc:bind:9.2.5:*:*:*:*:*:*:*
isc bind 9.2.5 cpe:2.3:a:isc:bind:9.2.5:b2:*:*:*:*:*:*
isc bind 9.2.5 cpe:2.3:a:isc:bind:9.2.5:rc1:*:*:*:*:*:*
isc bind 9.2.6 cpe:2.3:a:isc:bind:9.2.6:*:*:*:*:*:*:*
isc bind 9.2.6 cpe:2.3:a:isc:bind:9.2.6:rc1:*:*:*:*:*:*
isc bind 9.3 cpe:2.3:a:isc:bind:9.3:*:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:*:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:b2:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:b3:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:b4:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:rc1:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:rc2:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:rc3:*:*:*:*:*:*
isc bind 9.3.0 cpe:2.3:a:isc:bind:9.3.0:rc4:*:*:*:*:*:*
isc bind 9.3.1 cpe:2.3:a:isc:bind:9.3.1:*:*:*:*:*:*:*
isc bind 9.3.1 cpe:2.3:a:isc:bind:9.3.1:b2:*:*:*:*:*:*
isc bind 9.3.1 cpe:2.3:a:isc:bind:9.3.1:rc1:*:*:*:*:*:*

References for CVE-2007-0494

URL Tags
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://docs.info.apple.com/article.html?artnum=305530
http://fedoranews.org/cms/node/2507
http://fedoranews.org/cms/node/2537
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495
http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html
http://marc.info/?l=bind-announce&m=116968519300764&w=2
http://secunia.com/advisories/23904 Patch Vendor Advisory
http://secunia.com/advisories/23924 Vendor Advisory
http://secunia.com/advisories/23943 Vendor Advisory
http://secunia.com/advisories/23944 Vendor Advisory
http://secunia.com/advisories/23972 Vendor Advisory
http://secunia.com/advisories/23974 Vendor Advisory
http://secunia.com/advisories/23977 Vendor Advisory
http://secunia.com/advisories/24014 Vendor Advisory
http://secunia.com/advisories/24048 Vendor Advisory
http://secunia.com/advisories/24054 Vendor Advisory
http://secunia.com/advisories/24083 Vendor Advisory
http://secunia.com/advisories/24129 Vendor Advisory
http://secunia.com/advisories/24203 Vendor Advisory
http://secunia.com/advisories/24284
http://secunia.com/advisories/24648 Vendor Advisory
http://secunia.com/advisories/24930 Vendor Advisory
http://secunia.com/advisories/24950 Vendor Advisory
http://secunia.com/advisories/25402 Vendor Advisory
http://secunia.com/advisories/25482
http://secunia.com/advisories/25649
http://secunia.com/advisories/25715
http://secunia.com/advisories/26909
http://secunia.com/advisories/27706
http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc
http://security.gentoo.org/glsa/glsa-200702-06.xml
http://securitytracker.com/id?1017573
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.494157
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1
http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm
http://www-1.ibm.com/support/docview.wss?uid=isg1IY95618
http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619
http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144
http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324
http://www.debian.org/security/2007/dsa-1254
http://www.isc.org/index.pl?/sw/bind/bind-security.php
http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8 Patch
http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4 Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2007:030
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html
http://www.redhat.com/support/errata/RHSA-2007-0044.html
http://www.redhat.com/support/errata/RHSA-2007-0057.html
http://www.securityfocus.com/bid/22231
http://www.trustix.org/errata/2007/0005
http://www.ubuntu.com/usn/usn-418-1
http://www.vupen.com/english/advisories/2007/1401
http://www.vupen.com/english/advisories/2007/1939
http://www.vupen.com/english/advisories/2007/2002
http://www.vupen.com/english/advisories/2007/2163
http://www.vupen.com/english/advisories/2007/2245
http://www.vupen.com/english/advisories/2007/2315
http://www.vupen.com/english/advisories/2007/3229
https://exchange.xforce.ibmcloud.com/vulnerabilities/31838
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488
https://issues.rpath.com/browse/RPL-989
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11523
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144
cvelogic Threat Intelligence