CVE-2002-1220: Medium severity ISC BIND vulnerability
Published Nov 29, 2002
·Updated
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.
Affected Software
11 affected components
ISC BIND=8.3.1
ISC BIND=8.3.2
ISC BIND=8.3.0
ISC BIND=8.3.3
OpenBSD OpenBSD=3.1
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.7
FreeBSD FreeBSD=4.4
OpenBSD OpenBSD=3.2
OpenBSD OpenBSD=3.0
FreeBSD FreeBSD=4.6
Remediation
Patch Available
Event History
Nov 29, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1220?
CVE-2002-1220 is classified as a denial of service vulnerability that can cause system termination.
2
How do I fix CVE-2002-1220?
To fix CVE-2002-1220, upgrade to a non-vulnerable version of BIND, specifically versions above 8.3.3.
3
Which versions of BIND are affected by CVE-2002-1220?
CVE-2002-1220 affects BIND versions 8.3.0 to 8.3.3.
4
What type of attack does CVE-2002-1220 exploit?
CVE-2002-1220 exploits the handling of OPT resource records with large UDP payload sizes.
5
Can CVE-2002-1220 impact FreeBSD or OpenBSD systems?
Yes, CVE-2002-1220 can also impact specific versions of FreeBSD and OpenBSD that use the vulnerable versions of BIND.