Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
2007-01-25T20:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | isc | bind | 9.3.0 | Yes |
Application | isc | bind | 9.3.1 | Yes |
Application | isc | bind | 9.3.2 | Yes |
Application | isc | bind | 9.4.0 | Yes |
Application | isc | bind | 9.4.0 | Yes |
Application | isc | bind | 9.5.0 | Yes |