CVE-2002-2211: Medium severity ISC BIND vulnerability
BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2211?
CVE-2002-2211 has a medium severity rating due to its potential for DNS cache poisoning.
How do I fix CVE-2002-2211?
To fix CVE-2002-2211, upgrade to a non-vulnerable version of BIND, specifically versions later than the affected ones.
What versions of BIND are affected by CVE-2002-2211?
CVE-2002-2211 affects BIND versions 4.9.x and 8.2.x.
How can CVE-2002-2211 be exploited?
CVE-2002-2211 can be exploited by attackers performing a birthday attack with a large number of open queries and spoofed responses.
What impact does CVE-2002-2211 have on DNS servers?
The impact of CVE-2002-2211 on DNS servers can lead to unauthorized cache entries and possible redirection of users to malicious sites.