CVE-2002-1221

Description

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.297

Associated Vulnerability

VulnerabilityOS Platform
Update bind 8.3.3 to latest versionWindows
Multiple Vulnerabilities are affected in BIND 8.1Windows
Vulnerabilities CVE-1999-0009,CVE-1999-0849,CVE-2002-1221 are affected in BIND 8.1.1Windows
Multiple Vulnerabilities are affected in BIND 8.2Windows
Multiple Vulnerabilities are affected in BIND 8.2.1Windows
Multiple Vulnerabilities are affected in BIND 8.2.2Windows
Multiple Vulnerabilities are affected in BIND 8.2.4Windows
Multiple Vulnerabilities are affected in BIND 8.2.3Windows
Multiple Vulnerabilities are affected in BIND 8.2.5Windows
Multiple Vulnerabilities are affected in BIND 8.2.6Windows
Multiple Vulnerabilities are affected in BIND 8.3.0Windows
Multiple Vulnerabilities are affected in BIND 8.3.1Windows
Multiple Vulnerabilities are affected in BIND 8.3.2Windows
Multiple Vulnerabilities are affected in BIND 8.3.3Windows
Vulnerabilities CVE-2002-1221 are affected in BIND 8.1.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234