Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Bind | — | Apply OS X security update 2007-005 | Dec 16, 2011 | Jan 25, 2007 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 25, 2007 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Oct 5, 2011 | Jan 25, 2007 |
| Freebsd | — | Upgrade namedUpgrade FreeBSD | Dec 10, 2025 | Feb 27, 2007 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 25, 2007 |
| Oracle_linux | — | Upgrade bind-libsUpgrade caching-nameserverUpgrade bind-utilsUpgrade bind-develUpgrade bind-sdbUpgrade bind-chrootUpgrade bindUpgrade bind-libbind-devel | Oct 16, 2024 | Jan 25, 2007 |
| Suse | — | Upgrade bindUpgrade bind-libs-64bitUpgrade bind-libsUpgrade suse-releaseUpgrade bind-utilsUpgrade bind-libs-32bit | Feb 17, 2015 | Jan 25, 2007 |
| Ubuntu | — | Upgrade libdns21Upgrade libdns20 | Nov 8, 2024 | Jan 25, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub