CVE-2002-0684
Last modified
CVE-2002-0684 is a vulnerability of currently unknown severity. Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.. EPSS estimates a 5.86% chance of exploitation in the next 30 days.
Description
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | <= 2.2.5 |
| Isc | Bind | 4.9.8 |
References
- http://rhn.redhat.com/errata/RHSA-2002-139.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/542971US Government Resource
- http://rhn.redhat.com/errata/RHSA-2002-139.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/542971US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0684?
How severe is CVE-2002-0684?
How do I fix CVE-2002-0684?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0678CDE ToolTalk database server (ttdbserver) allows local users…
- CVE-2002-0679Buffer overflow in Common Desktop Environment (CDE) ToolTalk…
- CVE-2002-0680Directory traversal vulnerability in GoAhead Web Server 2.1 …
- CVE-2002-0681Cross-site scripting vulnerability in GoAhead Web Server 2.1…
- CVE-2002-0682Cross-site scripting vulnerability in Apache Tomcat 4.0.3 al…
- CVE-2002-0683Directory traversal vulnerability in Carello 1.3 allows remo…
- CVE-2002-0685Heap-based buffer overflow in the message decoding functiona…
- CVE-2002-0686Buffer overflow in the search component for iPlanet Web Serv…
- CVE-2002-0687The "through the web code" capability for Zope 2.0 through 2…
- CVE-2002-0688ZCatalog plug-in index support capability for Zope 2.4.0 thr…
- CVE-2002-0690Format string vulnerability in McAfee Security ePolicy Orche…
- CVE-2002-0691Microsoft Internet Explorer 5.01 and 5.5 allows remote attac…
Are you affected by CVE-2002-0684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
