CVE-2002-1221
Description
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.
Risk Information
Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.297
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update bind 8.3.3 to latest version | Windows |
| Multiple Vulnerabilities are affected in BIND 8.1 | Windows |
| Vulnerabilities CVE-1999-0009,CVE-1999-0849,CVE-2002-1221 are affected in BIND 8.1.1 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2.1 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2.2 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2.4 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2.3 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2.5 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.2.6 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.3.0 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.3.1 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.3.2 | Windows |
| Multiple Vulnerabilities are affected in BIND 8.3.3 | Windows |
| Vulnerabilities CVE-2002-1221 are affected in BIND 8.1.2 | Windows |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234