VDB
CVE-2002-1219
CVE-2002-1219
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).
EPSS 11.80% · 93.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
11.80%
93.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openbsd | openbsd | 3.2, 3.0, 3.1 |
| freebsd | freebsd | 4.5, 4.4, 4.6 |
| isc | bind | 8.2.1, 8.2.3, 8.2.4 |
Timeline
- Nov 29, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- CA-2002-31 third-party-advisory
- http://www.isc.org/products/BIND/bind-security.html url
- 2002-11-21 vendor-advisory
- 20021201-01-P vendor-advisory
- 6160 vdb
- DSA-196 vendor-advisory
- SSRT2408 vendor-advisory
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F48818 url
- oval:org.mitre.oval:def:2539 vdb
- 20021118 TSLSA-2002-0076 - bind mailing-list
- CLA-2002:546 vendor-advisory
- 20021115 [OpenPKG-SA-2002.011] OpenPKG Security Advisory (bind, bind8) mailing-list
- 20021112 [Fwd: Notice of serious vulnerabilities in ISC BIND 4 & 8] mailing-list
- N-013 third-party-advisory
- VU#852283 third-party-advisory
- bind-sig-rr-bo(10304) vdb
- 20021112 Multiple Remote Vulnerabilities in BIND4 and BIND8 third-party-advisory
- MDKSA-2002:077 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-1219 advisory