CVE-2002-0029: Buffer Overflow
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0029?
CVE-2002-0029 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2002-0029?
To mitigate CVE-2002-0029, upgrade ISC BIND to a version that is not affected, specifically versions above 4.9.10.
Which software is affected by CVE-2002-0029?
CVE-2002-0029 affects ISC BIND versions 4.9.2 through 4.9.10, and some derived libraries such as BSD libc and GNU glibc.
What types of attacks exploit CVE-2002-0029?
CVE-2002-0029 allows remote attackers to execute arbitrary code through specially crafted DNS server responses.
When was CVE-2002-0029 disclosed?
CVE-2002-0029 was disclosed in 2002 and continues to pose risks to affected systems.