CVE-2002-0400

Description

ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
27.728

Associated Vulnerability

VulnerabilityOS Platform
Update bind 9.2 to latest versionWindows
Multiple Vulnerabilities are affected in BIND 9.1.2Windows
Multiple Vulnerabilities are affected in BIND 9.0Windows
Multiple Vulnerabilities are affected in BIND 9.1Windows
Multiple Vulnerabilities are affected in BIND 9.1.1Windows
Multiple Vulnerabilities are affected in BIND 9.1.3Windows
Multiple Vulnerabilities are affected in BIND 9.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234