CVE-2002-1221: Medium severity ISC BIND vulnerability
Published Nov 29, 2002
·Updated
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.
Affected Software
21 affected components
ISC BIND=8.1
ISC BIND=8.1.1
ISC BIND=8.1.2
ISC BIND=8.2
ISC BIND=8.2.1
ISC BIND=8.2.2
ISC BIND=8.2.3
ISC BIND=8.2.4
ISC BIND=8.2.5
ISC BIND=8.2.6
ISC BIND=8.3.0
ISC BIND=8.3.1
ISC BIND=8.3.2
ISC BIND=8.3.3
FreeBSD FreeBSD=4.4
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.6
FreeBSD FreeBSD=4.7
OpenBSD OpenBSD=3.0
OpenBSD OpenBSD=3.1
OpenBSD OpenBSD=3.2
Remediation
Patch Available
Event History
Nov 29, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1221?
CVE-2002-1221 has a severity that can lead to a denial of service by crashing the BIND server.
2
How do I fix CVE-2002-1221?
To fix CVE-2002-1221, upgrade to a patched version of BIND that addresses this vulnerability.
3
Which versions of BIND are affected by CVE-2002-1221?
CVE-2002-1221 affects BIND versions 8.1 through 8.3.3.
4
Can CVE-2002-1221 be exploited remotely?
Yes, CVE-2002-1221 can be exploited remotely by attackers sending specially crafted requests.
5
What type of attack is CVE-2002-1221 associated with?
CVE-2002-1221 is associated with denial of service attacks that cause crashes in the BIND software.