7.5
CVE-2002-0029
- EPSS 9.86%
- Veröffentlicht 29.11.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:56:37
- Erkennungen
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Astaro ≫ Security Linux Version 2.0.23
Astaro ≫ Security Linux Version 2.0.24
Astaro ≫ Security Linux Version 2.0.25
Astaro ≫ Security Linux Version 2.0.26
Astaro ≫ Security Linux Version 2.0.27
Astaro ≫ Security Linux Version 2.0.30
Astaro ≫ Security Linux Version 3.2.0
Astaro ≫ Security Linux Version 3.2.10
Astaro ≫ Security Linux Version 3.2.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.86% | 0.95 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-028.txt.asc
ftp://patches.sgi.com/support/free/security/advisories/20021201-01-P
http://lists.apple.com/archives/Security-announce/2002/Nov/msg00000.html
http://www.cert.org/advisories/CA-2002-31.html
http://www.isc.org/products/BIND/bind-security.html
http://www.iss.net/security_center/static/10624.php
http://www.kb.cert.org/vuls/id/844360
http://www.securityfocus.com/bid/6186