First published: Tue Dec 31 2002(Updated: )
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND 9 | =8.2.2-p7 | |
ISC BIND 9 | =8.2 | |
ISC BIND 9 | =4.9.5-p1 | |
ISC BIND 9 | =4.9.4 | |
ISC BIND 9 | =8.2.1 | |
ISC BIND 9 | =8.2.2-p1 | |
ISC BIND 9 | =8.2.5 | |
ISC BIND 9 | =8.3.1 | |
ISC BIND 9 | =8.3.2 | |
ISC BIND 9 | =8.2.2-p4 | |
ISC BIND 9 | =4.9.8 | |
ISC BIND 9 | =8.2.2-p2 | |
ISC BIND 9 | =8.3.4 | |
ISC BIND 9 | =4.9.6 | |
ISC BIND 9 | =8.2.7 | |
ISC BIND 9 | =8.2.2 | |
ISC BIND 9 | =8.2.4 | |
ISC BIND 9 | =8.2.2-p6 | |
ISC BIND 9 | =4.9.10 | |
ISC BIND 9 | =4.9 | |
ISC BIND 9 | =8.2.6 | |
ISC BIND 9 | =4.9.3 | |
ISC BIND 9 | =4.9.7 | |
ISC BIND 9 | =8.2.2-p5 | |
ISC BIND 9 | =8.3.0 | |
ISC BIND 9 | =8.2.2-p3 | |
ISC BIND 9 | =8.3.3 | |
ISC BIND 9 | =4.9.9 | |
ISC BIND 9 | =4.9.5 | |
ISC BIND 9 | =4.9.2 | |
ISC BIND 9 | =8.2.3 | |
Fujitsu Uxp V |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2212 is classified as a high severity vulnerability due to its potential to enable DNS cache poisoning.
To fix CVE-2002-2212, upgrade to the latest version of BIND or apply available patches to mitigate the risk.
CVE-2002-2212 affects multiple versions of BIND including 4.9, 8.2.x, and various 8.3.x releases.
Yes, CVE-2002-2212 can be exploited remotely through crafted DNS queries and responses.
DNS cache poisoning refers to the ability of an attacker to insert false DNS records into the cache, redirecting users to malicious sites.