CVE-2001-0012: Medium severity ISC BIND vulnerability
Published Feb 12, 2001
·Updated
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.
Affected Software
15 affected components
ISC BIND=4.9.3
ISC BIND=4.9.5
ISC BIND=4.9.5-p1
ISC BIND=4.9.6
ISC BIND=4.9.7
ISC BIND=8.2
ISC BIND=8.2.1
ISC BIND=8.2.2
ISC BIND=8.2.2-p1
ISC BIND=8.2.2-p2
ISC BIND=8.2.2-p3
ISC BIND=8.2.2-p4
ISC BIND=8.2.2-p5
ISC BIND=8.2.2-p6
ISC BIND=8.2.2-p7
Remediation
Patch Available
Event History
Feb 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0012?
CVE-2001-0012 is classified as a medium severity vulnerability.
2
How do I fix CVE-2001-0012?
To remediate CVE-2001-0012, upgrade to a version of BIND that is not affected, such as BIND 9 or the latest BIND 8 versions.
3
What impact does CVE-2001-0012 have on my system?
CVE-2001-0012 allows remote attackers to access sensitive information including environment variables from the affected BIND software.
4
Which versions of BIND are affected by CVE-2001-0012?
CVE-2001-0012 affects BIND 4.9.3 through 4.9.7 and BIND 8 series versions up to 8.2.2.
5
Is there a workaround for CVE-2001-0012?
While upgrading is the best option, a potential workaround includes configuring BIND to restrict external queries if immediate patching is not feasible.