CVE-2002-2212: Medium severity ISC BIND vulnerability
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2212?
CVE-2002-2212 is classified as a high severity vulnerability due to its potential to enable DNS cache poisoning.
How do I fix CVE-2002-2212?
To fix CVE-2002-2212, upgrade to the latest version of BIND or apply available patches to mitigate the risk.
What versions of BIND are affected by CVE-2002-2212?
CVE-2002-2212 affects multiple versions of BIND including 4.9, 8.2.x, and various 8.3.x releases.
Can CVE-2002-2212 be exploited remotely?
Yes, CVE-2002-2212 can be exploited remotely through crafted DNS queries and responses.
What does DNS cache poisoning mean in the context of CVE-2002-2212?
DNS cache poisoning refers to the ability of an attacker to insert false DNS records into the cache, redirecting users to malicious sites.