CVE-2001-0010: Buffer Overflow
Published Feb 12, 2001
·Updated
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
Affected Software
10 affected components
ISC BIND=8.2.2-p7
ISC BIND=8.2
ISC BIND=8.2.1
ISC BIND=8.2.2-p1
ISC BIND=8.2.2-p4
ISC BIND=8.2.2-p2
ISC BIND=8.2.2
ISC BIND=8.2.2-p6
ISC BIND=8.2.2-p5
ISC BIND=8.2.2-p3
Remediation
Patch Available
Patch Available
Event History
Feb 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0010?
CVE-2001-0010 is categorized as a critical severity vulnerability due to the potential for remote root privilege escalation.
2
How do I fix CVE-2001-0010?
To fix CVE-2001-0010, upgrade to a patched version of BIND 8, specifically a version later than 8.2.2-p7.
3
What impact does CVE-2001-0010 have on BIND 8?
CVE-2001-0010 allows remote attackers to exploit a buffer overflow, leading to unauthorized root access.
4
Which versions of BIND 8 are affected by CVE-2001-0010?
CVE-2001-0010 affects BIND 8, specifically versions including 8.2, 8.2.1, and several patches of 8.2.2.
5
Can CVE-2001-0010 be exploited remotely?
Yes, CVE-2001-0010 can be exploited remotely, making it particularly dangerous for servers running vulnerable versions of BIND 8.