CVE-2002-0029

Description

Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka LIBRESOLV: buffer overrun and a different vulnerability than CVE-2002-0684.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
21.847

Associated Vulnerability

VulnerabilityOS Platform
Update bind 4.9.9 to latest versionWindows
Multiple Vulnerabilities are affected in BIND 4.9.6Windows
Multiple Vulnerabilities are affected in BIND 4.9.5Windows
Multiple Vulnerabilities are affected in BIND 4.9.7Windows
Multiple Vulnerabilities are affected in BIND 4.9.3Windows
Multiple Vulnerabilities are affected in BIND 4.9.10Windows
Vulnerabilities CVE-2002-0029,CVE-2002-2211,CVE-2002-2212,CVE-2002-2213 are affected in BIND 4.9.2Windows
Vulnerabilities CVE-2002-0029,CVE-2002-2211,CVE-2002-2212,CVE-2002-2213 are affected in BIND 4.9.4Windows
Multiple Vulnerabilities are affected in BIND 4.9.8Windows
Multiple Vulnerabilities are affected in BIND 4.9.9Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234