PT-2002-1050 · Gnu+2 · Glibc+2

Publicado

2002-07-03

·

Atualizado

2016-10-18

·

CVE-2002-0684

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.0 through 2.2.5 ISC BIND versions 4.9 through 9.2.1
Description The issue concerns buffer overflows in DNS resolver functions, including getnetbyname() and getnetbyaddr(), which handle network name and address lookups. A remote attacker in control of a DNS server could overflow a buffer and cause the system to crash or execute arbitrary code on the system with the same privileges as the process that calls the DNS resolver function.
Recommendations For glibc versions 2.0 through 2.2.5, update to a version that is not affected by this issue. For ISC BIND versions 4.9 through 9.2.1, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the DNS resolver functions until a patch is available. Avoid using the getnetbyname() and getnetbyaddr() functions in the affected API endpoints until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07993
BDU:2015-07994
BDU:2015-07997
BDU:2015-08004
BDU:2015-08005
BDU:2015-08008
BDU:2015-08009
CVE-2002-0684

Produtos afetados

Bind Server
Isc Bind
Glibc