CVE-2002-0684
Last modified
CVE-2002-0684 is a vulnerability of currently unknown severity. Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.. EPSS estimates a 5.86% chance of exploitation in the next 30 days.
Description
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | <= 2.2.5 |
| Isc | Bind | 4.9.8 |
References
- http://rhn.redhat.com/errata/RHSA-2002-139.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/542971US Government Resource
- http://rhn.redhat.com/errata/RHSA-2002-139.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/542971US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0684?
How severe is CVE-2002-0684?
How do I fix CVE-2002-0684?
Are you affected by CVE-2002-0684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
