CVE-2002-0400: Medium severity ISC BIND vulnerability
ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dnsmessagefindtype() function in message.c is not NULL, aka DoSfindtype.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0400?
CVE-2002-0400 has a severity rating that indicates it can cause denial of service, affecting the availability of the service.
How do I fix CVE-2002-0400?
To fix CVE-2002-0400, upgrade to BIND version 9.2.1 or later, which addresses this vulnerability.
Which versions of BIND are affected by CVE-2002-0400?
CVE-2002-0400 affects BIND versions 9.0 through 9.2, including 9.1.1, 9.1.2, 9.1.3, and 9.2.
What actions can attackers perform using CVE-2002-0400?
Attackers can exploit CVE-2002-0400 to send malformed DNS packets, leading to a denial of service that can shut down the DNS service.
Is CVE-2002-0400 still relevant today?
While CVE-2002-0400 is an older vulnerability, it serves as a reminder for the importance of keeping software updated to mitigate known issues.