CVE-2002-1219: Buffer Overflow
Published Nov 29, 2002
·Updated
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).
Affected Software
24 affected components
ISC BIND=8.2
ISC BIND=8.2.1
ISC BIND=8.2.5
ISC BIND=8.3.1
ISC BIND=8.3.2
ISC BIND=4.9.8
ISC BIND=4.9.6
ISC BIND=8.2.2
ISC BIND=8.2.4
ISC BIND=4.9.10
ISC BIND=8.2.6
ISC BIND=4.9.7
ISC BIND=8.3.0
ISC BIND=8.3.3
ISC BIND=4.9.9
ISC BIND=4.9.5
ISC BIND=8.2.3
OpenBSD OpenBSD=3.1
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.7
FreeBSD FreeBSD=4.4
OpenBSD OpenBSD=3.2
OpenBSD OpenBSD=3.0
FreeBSD FreeBSD=4.6
Remediation
Patch Available
Event History
Nov 29, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1219?
CVE-2002-1219 has a critical severity level as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2002-1219?
To fix CVE-2002-1219, upgrade to BIND version 8.3.4 or later and ensure your DNS server does not process SIG resource records from untrusted sources.
3
Which versions of BIND are affected by CVE-2002-1219?
CVE-2002-1219 affects ISC BIND versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier.
4
Can CVE-2002-1219 be exploited without authentication?
Yes, CVE-2002-1219 can be exploited remotely without requiring authentication.
5
What types of attacks can result from CVE-2002-1219?
Exploitation of CVE-2002-1219 can lead to remote code execution and denial of service attacks.