CVE-2002-2213: Medium severity isc bind vulnerability
The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2213?
CVE-2002-2213 has a high severity level, as it allows remote attackers to perform DNS cache poisoning.
How do I fix CVE-2002-2213?
To fix CVE-2002-2213, upgrade to the latest version of ISC BIND or Infoblox DNS One that addresses this vulnerability.
What types of attacks can be conducted using CVE-2002-2213?
CVE-2002-2213 enables attackers to conduct DNS cache poisoning attacks via a birthday attack.
Which versions of software are affected by CVE-2002-2213?
CVE-2002-2213 affects various versions of ISC BIND, specifically versions 4.9.x and 8.2.x, as well as unspecified versions of Infoblox DNS One.
How does CVE-2002-2213 allow for DNS cache poisoning?
CVE-2002-2213 facilitates DNS cache poisoning by exploiting the use of a large number of open queries for the same resource record combined with spoofed responses.